slimovich/Realworld-fastapi-gino-template
54.3
Adequate · 22 September 2026
368
lines of production code
Python
primary language
7
measurements over time
What this system is
This system is a Python-based web application built with FastAPI, designed to manage user data through a structured domain-driven architecture. It provides a complete CRUD API for user management, supported by a PostgreSQL database with Alembic migrations and Gino ORM integration. The codebase emphasizes strict separation of concerns, utilizing dependency injection, explicit configuration, and comprehensive test coverage for both API and domain layers.
Features
Added SQL utility for database existence checks
A new utility module at src/utils/sql.py was added, providing an async function to check if a specific database name exists in a PostgreSQL instance using Gino. This introduces a new capability for database validation within the application's utility layer.
src/utils · high confidence
Initial database migration for user base table
Added the initial Alembic migration configuration and template, along with the first migration script that creates the 'user base' table. This table includes columns for id, email, full\_name, password, is\_active, is\_superuser, and created\_date, establishing the foundational schema for user data.
src/infrastructure/database/migration · high confidence
Initial project scaffolding and development tooling
The repository was initialized with a comprehensive set of development and build configurations. This includes a Makefile for managing build, test, and linting tasks, alongside dedicated Dockerfiles for development and production environments. The project also introduces environment variable files for local, development, and production setups, as well as configuration files for code quality tools (flake8, mypy, isort, black, bandit) and SonarQube integration. Additionally, a LICENSE file (MIT) and an updated README with project documentation were added.
(repo-wide) · high confidence
Introduce user management API endpoints
The API now exposes a complete set of endpoints for managing users, including creating, listing, retrieving by ID, updating, and deleting users. These endpoints are implemented in src/api/endpoints/user.py and wired into the main application via src/api/api.py, which was updated to import the new user router from the endpoints package. The implementation relies on a UserService injected via dependency injection, as defined in src/api/utils.py.
src/api · high confidence
Removals
Removal of user router module
The user router module, which previously exposed endpoints for creating, listing, retrieving, updating, and deleting users, has been removed from the codebase. This eliminates the associated API routes and the associated service injection logic for user management.
src/api/userRouter · high confidence
Behavioural changes
Refactor core application initialization and server configuration
The application's startup behavior has changed: the server now checks for the existence of the database before attempting to create tables, and will log an error if the database is missing. Additionally, the server's host, port, and log level are now explicitly configured via environment variables or default values in config.py, replacing hardcoded values. The previous dependency injection setup (inject library) has been removed, and the CLI tool has been expanded with new commands for database management (create, migration, migrate) using Click and subprocess calls.
src/core · high confidence
Restructure Docker and setup scripts for distinct development and production environments
The project now supports separate configurations for development and production. A new \docker-compose.production.yml\ file has been added to define the production environment, while the existing \docker-compose.yml\ has been renamed to \docker-compose.develop.yml\ and updated to use environment variables for database credentials. Additionally, the \setEnv.sh\ script was added to configure the local environment, while the previous \start.sh\ and \start\_local.sh\ scripts were removed.
setup · medium confidence
Restructured user management domain with updated schemas and interfaces
The user management domain has been restructured: the \UserService\ implementation was moved from \src/domain/userManagment/service/userService.py\ to \src/domain/userManagment/userService.py\, and the \IUserQueries\ interface was moved and renamed to \src/domain/userManagment/queriesInterface.py\. Additionally, the \UserDBSchema\ was updated to enforce that \user\_id\ is a required integer field rather than an optional one, and the schema files were consolidated into \userSchema.py\.
src/domain · high confidence
Restructured user model and query interface
The user model file was refactored to update import paths for the query interface and schema definitions, and the UserQueries class was expanded to include a delete\_user method alongside the existing create, update, and get methods.
src/infrastructure/database/models · medium confidence
Test coverage
Expanded test coverage for user service operations; Updated user router tests to cover full CRUD operations.
Dependencies
Update Python dependencies to specific versions
The project's Python dependencies have been updated to specific, pinned versions in the Pipfile and Pipfile.lock. Notable changes include upgrading FastAPI from 0.46.0 to 0.58.1, Gino from 0.8.7 to 1.0.0, and adding new dependencies such as gino-starlette, entrypoints, and bandit. Several packages like pytest, requests, and mypy have also been updated to newer, explicitly versioned releases.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 52 → 54 (+2.7)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 59 → 59 (+0.0)
- Readiness 33 → 38 (+4.8)
- Security 66 → 69 (+3.2)
- Domain Modelling 100 → 100 (+0.0)
Resolved (28)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (Pipfile.lock)
- Critical CVE: [GHSA redacted] (Pipfile.lock)
- Critical CVE: [GHSA redacted] (Pipfile.lock)
- Dependency hygiene not measured — no supported dependency manifest was read
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (Pipfile.lock)
- Medium CVE: [GHSA redacted] (Pipfile.lock)
- Medium CVE: [GHSA redacted] (Pipfile.lock)
- Medium CVE: [GHSA redacted] (Pipfile.lock)
- Medium CVE: [GHSA redacted] (Pipfile.lock)
- …and 8 more
New (39)
- Critical CVE: [GHSA redacted] (Pipfile.lock)
- Critical CVE: [GHSA redacted] (Pipfile.lock)
- Critical CVE: [GHSA redacted] (Pipfile.lock)
- Documentation: no project overview (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High CVE: [GHSA redacted] (Pipfile.lock)
- High IaC: WD-COMPOSE-0002 (setup/docker/docker-compose.develop.yml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low IaC: DS-0026 (docker-develop.dockerfile)
- Low IaC: DS-0026 (docker-production.dockerfile)
- …and 19 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
slimovich/Realworld-fastapi-gino-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a350b318139856aa0448abe536ebf263b8691570 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.