Skip to content
CAI
Software that uses CAICheck a score

santoshshinde2012/node-boilerplate

71.1

Strong · 21 September 2026

1.1k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add encryption and logging utilities

Added src/lib/crypto.ts, which provides AES-256-GCM encryption and decryption with PBKDF2 key derivation, and src/lib/logger.ts, which configures a Winston-based logger that writes to console and files while gracefully handling read-only filesystems.

src/lib · high confidence

Added structured request logging, error handling, and request ID middleware

Added three new middleware components in the src/middleware directory: error-handler.ts provides a centralized, structured error response that omits stack traces in production to prevent information exposure; request-id.ts generates or validates a safe request ID header; and request-logger.ts logs request metadata (method, path, status, duration) with appropriate log levels based on response status codes.

src/middleware · high confidence

Added utility for conditional data encryption

A new utility function, getEncryptedText, has been added to src/utils. This function conditionally encrypts input data using a secret key from environment variables, allowing users to enable data protection at runtime via the APPLY\_ENCRYPTION flag.

src/utils · high confidence

Introduce structured error and response abstractions

Added new TypeScript files defining an \ApiError\ class and \IStandardResponse\ interface to standardize how API errors and success responses are structured across the application.

src/abstractions · high confidence

New system status endpoints with production-safe data filtering

Added a new SystemStatusController that exposes /system/info, /system/time, /system/usage, /system/process, and /system/error. In production, the /info and /process endpoints automatically strip sensitive details (network interfaces, user info, environment variables) to prevent information leakage, while development mode returns the full data.

src/components/system-status · high confidence

Production hardening and security defaults

The project has been upgraded to a production-ready Node.js + TypeScript boilerplate with hardened security defaults. A hardened multi-stage Dockerfile runs the app as a non-root user with dropped Linux capabilities, read-only filesystems, and a built-in healthcheck. The runtime enforces a global rate limiter, body-size limits, allow-listed CORS origins, and encrypted response payloads. System diagnostic endpoints are filtered in production, and the app fails fast on missing or invalid configuration. The build system now uses TypeScript's native module resolution (ES2022/Node16) and a flat ESLint config, while legacy tooling (tslint, index.js) has been removed.

(repo-wide) · high confidence

Removals

Removal of legacy recording dependencies and build scripts

The repository has removed the \build-scripts/version-gen.js\ build script and the \public/scripts/RecordRTC.js\ and \public/scripts/RecordRTC.min.js\ client-side recording libraries. This change eliminates the legacy RecordRTC-based audio, video, and canvas recording capabilities from the application.

(repo-wide) · high confidence

Removed Keycloak integration components

The Keycloak controller and associated API routes have been removed from the application. This eliminates the server-side endpoints for listing users and groups via the Keycloak Admin API, meaning the application no longer exposes or manages Keycloak user and group data through these specific routes.

src/components/keyclock · high confidence

Behavioural changes

Centralized configuration management for production hardening

A new centralized configuration module has been introduced to manage application settings, supporting environment-specific behavior for development, test, staging, and production. This change enforces stricter security defaults in production, including rate limiting, CORS origin validation, and encryption key validation, while providing a structured interface for application settings such as port, log level, and system route exposure.

src/config · high confidence

Git pre-commit and pre-push hooks configured

The project now includes automated checks that run before commits and pushes. A pre-commit hook executes 'npm run precommit' to validate changes, and a pre-push hook runs 'npm run prepush' to verify the state before pushing. These hooks are set up with executable permissions to ensure they run automatically.

.husky · high confidence

Production hardening and security improvements

The application now includes robust production hardening, including security headers via Helmet, rate limiting, and safe CORS configuration. The server startup logic has been updated to handle graceful shutdowns and enforce HTTP timeouts to prevent slow-loris and stuck connections. Additionally, the routing system has been refactored to use a controller-based approach with a /v1 prefix, and Swagger documentation is now mounted for non-production environments.

src · medium confidence

Fixes

Introduce BaseController for shared API response handling

A new abstract BaseController class has been added to the components directory, providing a centralized way to send encrypted API responses. This change introduces a shared implementation for the send method, which handles response status and encryption, reducing duplication across controllers.

src/components · medium confidence

Removed environment configuration files

The \environment.local.ts\ and \environment.ts\ files in the \src/environments\ directory have been deleted. This removes the previous mechanism for loading environment variables (including Keycloak and port configurations) and the function that selected the environment configuration based on \NODE\_ENV\.

src/environments · high confidence

Test coverage

Added integration test helper for application setup; Added integration tests for app status endpoints; Added unit tests for SystemStatusController and utility functions; Added unit tests for crypto and route registration; Added unit tests for the error handler middleware.

Dependencies

Upgraded Node.js dependencies and tooling

The project's dependencies have been significantly updated. Runtime packages like Express, Winston, and Dotenv have been upgraded to their latest major versions, while development tools such as TypeScript, ESLint, Prettier, and Jest have also been updated to their newest releases. This includes a major upgrade to the ESLint configuration, replacing TSLint with the modern typescript-eslint and @eslint/js packages.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 77 → 71 (-5.5)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 99 (+1.5)
  • Architecture 69 → 69 (+0.0)
  • Maturity 84 → 67 (-16.4)
  • Readiness 87 → 74 (-13.2)
  • Security 78 → 81 (+3.3)

Resolved (23)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (package-lock.json)
  • Low CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • …and 3 more

New (47)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 27 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

santoshshinde2012/node-boilerplate was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1f57b0197ad5143f92688fa6b24dacde52926cb1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.