Skip to content
CAI
Software that uses CAICheck a score

TheGoatedDev/EnterpriseNest

56.1

Adequate · 21 September 2026

5.8k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an enterprise-grade NestJS application scaffolding that provides a modular, CQRS-based architecture for handling authentication, session management, and user administration. It implements secure JWT-based access and refresh token flows, role-based access control, and distributed tracing via OpenTelemetry. The codebase also includes infrastructure for email and SMS notifications, rate limiting, and standardized API responses with comprehensive testing utilities.

Features

Add SMS infrastructure with mock adapter and port definitions

The SMS infrastructure layer now includes a mock adapter and port definitions to support SMS functionality. The \sms.port.ts\ file defines the \SMSOptions\ interface and the \SMSPort\ interface, establishing the contract for sending SMS messages. The \sms.constants.ts\ file introduces the \SMS\ symbol for dependency injection. Additionally, the \mock.sms.service.ts\ file provides a mock implementation of the \SMSPort\ interface, logging SMS details without actual network calls, which is useful for testing and development environments.

src/infrastructure/sms · high confidence

Add ability to retrieve all active sessions for a user

Users can now retrieve a list of all their active sessions via a new API endpoint. This feature includes a query handler to fetch session data, a controller to expose the endpoint at /session/user/:userid, and a response DTO. The implementation enforces access control: regular users can only view their own sessions, while administrators can view any user's sessions.

src/application/session/v1/queries/find-all-sessions-by-user · high confidence

Add ability to retrieve session details by token

A new endpoint at GET /session/:token allows users to look up session information using a refresh token. The implementation includes a query handler that fetches the session from the repository and a controller that enforces ownership rules: non-admin users can only access their own sessions, while staff members can access any session. The response is wrapped in a standardized DTO containing the Session entity.

src/application/session/v1/queries/find-session-by-token · high confidence

Add authentication decorators for user, token, roles, and public access

New decorators are introduced in the authentication module to support access control and request parsing. The \CurrentUser\ decorator extracts the authenticated user from the request context, while the \Token\ decorator parses and returns the bearer token from the Authorization header. Additionally, the \Public\ decorator marks routes as accessible without authentication, and the \Roles\ decorator enables role-based access control by setting metadata for user roles.

src/application/authentication/decorator · high confidence

Add authentication metrics and verification email triggers

New event handlers have been added to the authentication flow to support observability and user verification. Successful logins and registrations now increment OpenTelemetry counters for user activity. Additionally, a new handler triggers the sending of verification emails upon user registration, while failed login attempts are tracked via specific counters for incorrect passwords and total attempts.

src/application/authentication/event-handlers · high confidence

Add email verification and confirmation endpoints

The application now exposes HTTP endpoints for sending and confirming email verification. Users can request a verification email via a new 'send verification' command, which generates a token, sends an email via the MailerPort, and publishes a 'verification sent' event. A corresponding 'confirm verification' command validates the token, updates the user's verified status, and publishes a 'verification confirmed' event. Additionally, a new event handler increments a counter metric each time a verification email is sent.

src/application/verification · high confidence

Add forgot-password endpoint for password reset requests

A new V1 API endpoint at /authentication/forgot-password allows users to request a password reset. The controller validates the user's email, and if found, triggers a command handler that generates a reset token and sends an email containing the token. The endpoint is rate-limited to one request per minute to mitigate brute-force attempts.

src/application/authentication/v1/commands/forgot-password · high confidence

Add full user management API (v1) with create, update, delete, and find operations

The user management module now exposes a complete set of v1 endpoints for creating, updating, and deleting users, as well as finding users by ID, email, or listing all users. The create endpoint automatically generates a random password and returns it in the response. The delete and update endpoints require admin-level access (AllStaffRoles) and handle not-found scenarios with appropriate 404 responses. The find-all and find-by-email/id endpoints provide read access for admins, while the find-current-user endpoint allows users to retrieve their own profile. All operations are wired through a new V1UserModule that registers the corresponding command/query handlers and HTTP controllers.

src/application/user · high confidence

Add health check endpoint

A new health check endpoint is now available at /health, allowing users to verify the status of the HTTP service and disk storage.

src/application/health/v1/queries · high confidence

Add logout endpoint to invalidate refresh tokens

A new logout endpoint is introduced at /authentication/logout, allowing users to log out and invalidate their refresh tokens. The endpoint is protected by a RefreshTokenGuard and calls the V1RevokeSessionCommandHandler to revoke the session.

src/application/authentication/v1/commands/logout · high confidence

Add mock user repository for testing

A mock implementation of the user repository has been introduced to support testing scenarios. This includes a new 'MockUserRepository' class that simulates user data storage and retrieval, along with a corresponding test file to verify its behavior. The mock repository handles user creation, updates, and email-based lookups, providing a convenient way to test components that depend on user data without needing a real database.

src/infrastructure/repositories/modules/user · high confidence

Add v1 Ping API endpoint with CQRS event publishing

A new v1 Ping API has been introduced, exposing a GET /ping endpoint that returns a standardized response containing a message, server time, and application name. The implementation leverages the CQRS module to publish a PingRanEvent upon each request, and includes an end-to-end test to verify the endpoint's behavior.

src/application/ping/v1 · high confidence

Add verification token generation capability

A new command and handler have been introduced to generate verification tokens for users. The system now creates a JWT-based verification token containing the user's ID, which is then published as an event. This enables downstream processes to verify user identity or perform account-related actions.

src/infrastructure/token/v1/commands/generate-refresh-token, src/infrastructure/token/v1/commands/generate-verification-token · high confidence

A new Session module has been introduced in the application layer, serving as a container that imports the V1SessionModule. This change establishes the structural foundation for handling session logic within the application.

src/application/session · medium confidence

Added confirm forgot password endpoint

A new API endpoint has been introduced to allow users to confirm a forgot password request and reset their password. This feature includes a new HTTP controller, command handler, and request DTO that validate the reset token and new password, updating the user's credentials and publishing a confirmation event.

src/application/authentication/v1/commands/confirm-forgot-password · high confidence

Added credential validation query handler

Users can now have their email and password validated through a new V1ValidateCredentialsQuery handler. This implementation checks the user's email against the database and verifies the password, throwing specific exceptions for no email match or incorrect password, and publishes an event upon completion.

src/application/authentication/v1/queries · high confidence

Added domain events for user attribute changes

Introduced new domain events to track specific user profile updates, including changes to email, first name, last name, password, role, and verification status. Each event captures the affected user entity along with the old and new values for the respective attribute, enabling downstream systems to react to these specific user state transitions.

src/domain/user/events · high confidence

Added health check endpoint via new V1HealthModule

A new V1HealthModule has been introduced to provide health check functionality. The module integrates @nestjs/terminus and @nestjs/axios, and registers the V1CheckHealthController to expose the health check endpoint.

src/application/health/v1 · high confidence

Added query handlers to verify reset password and email verification tokens

Users can now have their reset password and email verification tokens validated through new query handlers. The system verifies the JWT tokens against their respective secrets, checks the token type (reset-password or verification), and retrieves the associated user. If a token is invalid, expired, or the user is not found, an unauthenticated exception is thrown.

src/infrastructure/token/v1/queries · high confidence

Added reset password token generation capability

Users can now generate a reset password token, which is signed as a JWT containing the user's ID and a 'reset-password' type. The system publishes an event upon generation, enabling downstream processes to react to the new token.

src/infrastructure/token/v1/commands/generate-access-token, src/infrastructure/token/v1/commands/generate-reset-password-token · high confidence

Added session creation capability for users

Introduced a new command and handler to create user sessions. The \V1CreateSessionCommand\ accepts a \User\ and an optional IP address. The corresponding handler validates the user's existence, creates a new \Session\ entity with the provided IP, persists it via the session repository, and returns the new session object. A unit test was added to verify the happy path and the case where the user is not found.

src/application/session/v1/commands/create-session · high confidence

Added session query endpoints for current user

Introduced new HTTP controllers and response DTOs for retrieving session data. The /session/me endpoint allows users to fetch their current active session, while the /session/user/me endpoint retrieves all sessions associated with the current user. These changes expose the underlying query handlers via a standardized API response format, enabling clients to interact with session data through dedicated API routes.

src/application/session/v1/queries/find-all-sessions-by-current-user, src/application/session/v1/queries/find-current-session · high confidence

Added session revocation endpoint

Users can now revoke an active session by sending a DELETE request to /session/:token. The controller validates that the user owns the session (or has the appropriate role) before executing the revocation, returning the updated session object in the response.

src/application/session/v1/commands/revoke-session · high confidence

Added verification event classes for user confirmation and email sending

New event classes have been introduced in the verification domain to track user verification states. Specifically, OnVerificationConfirmedEvent is added to represent the moment a user's verification is confirmed, while OnVerificationSentEvent captures the sending of a verification email, including the user and the associated token. These changes support the internal tracking of verification lifecycle events.

src/domain/verification · high confidence

Automated template remote setup and merge script

A new shell script, template-remote.sh, has been added to automate the process of setting up a remote for a template repository, fetching its changes, and creating a pull request. The script handles cleaning up existing template remotes and branches, merges the template's main branch into the current branch, and uses the GitHub CLI to create an auto-merge pull request.

scripts · high confidence

Implement access token authentication with session validation

Added new access token authentication strategy and guard for the NestJS application. The strategy validates the JWT payload, ensuring the token type is 'access-token' and contains required fields like user ID, refresh token, and IP address. It then verifies the user exists, is verified, and has an active, non-revoked session associated with the provided refresh token. The accompanying guard enforces public route exemptions and role-based access control, throwing specific unauthenticated or no-permission exceptions when validation fails.

src/application/authentication/strategies/access-token · high confidence

Initial project scaffolding and configuration

The repository is initialized with essential configuration files to support development and deployment. This includes a Dockerfile with a healthcheck, a .env.template for environment variables (including JWT and token secrets), and a .gitignore/.dockerignore to exclude unnecessary files. Build and linting tools are configured via tsup.config.ts (with minification and treeshaking), tsconfig.json, and biome.json. Additionally, Jest is set up for testing, and a README.md provides an overview of the Enterprise-Nest framework.

(repo-wide) · high confidence

Introduce OpenTelemetry tracing and Redis-based rate limiting

The application now includes OpenTelemetry instrumentation for observability, initializing the SDK via src/shared/utilities/tracing.ts. Additionally, a new throttler module (src/infrastructure/throttler/throttler.module.ts) has been added to support rate limiting, with optional Redis storage for distributed state.

src · high confidence

Introduce V1SessionModule for session management

Added V1SessionModule which registers controllers and handlers for session operations, including creating, revoking, and finding sessions by token or current user.

src/application/session/v1 · high confidence

Introduce global cache and CQRS module scaffolding

The application now registers a global CacheModule that configures either an in-memory or Redis-backed cache store based on configuration, and a CQRSModule that wires up the NestJS CQRS module while adding debug logging for all events, commands, and queries.

src/infrastructure/cache, src/infrastructure/cqrs · high confidence

Introduce global logger module with OpenTelemetry tracing integration

A new global LoggerModule has been added to the infrastructure layer, integrating pino for logging with automatic injection of OpenTelemetry span and trace IDs (spanId, traceId) and user context (userId, userEmail) into log records. In development, logs are formatted with pino-pretty, while production logs include distributed tracing metadata to improve observability and debugging.

src/infrastructure/logger · high confidence

Introduce local authentication strategy with email/password validation

The local authentication strategy is now implemented via a new guard and strategy class. Users can log in using their email and password. The system validates credentials, handles specific authentication failures (such as unverified accounts or incorrect passwords), and publishes an event if a user attempts to log in without being verified.

src/application/authentication/strategies/local · high confidence

Introduce mock repository abstraction for development and testing

Developers can now use an in-memory mock repository implementation for all entity types during development or testing, enabling faster, database-free operations. The \AbstractMockRepository\ provides in-memory CRUD and paginated find-all capabilities, while the \RepositoriesModule\ conditionally registers either the mock or real repository implementations based on the \NODE\_ENV\ environment variable.

src/infrastructure/repositories · high confidence

Introduce refresh token authentication strategy and guard

Added a new refresh token authentication strategy and guard to the application. The strategy validates the refresh token payload, checks for IP address consistency between the request and the stored session, and ensures the session has not been revoked. This provides a dedicated mechanism for handling refresh token validation and user retrieval.

src/application/authentication/strategies/refresh-token · high confidence

Introduce session domain model and lifecycle events

The session domain now includes a new \Session\ entity that manages user session data, including user ID, token, IP address, and revocation status. The entity provides a \create\ factory method that generates a unique ID and token, and a \revoke\ method that marks the session as revoked and publishes an \OnSessionRevokedEvent\. Three new domain events have been added: \OnSessionCreatedEvent\, \OnSessionDeletedEvent\, and \OnSessionRevokedEvent\, each carrying the associated \Session\ instance. A \SessionData\ class and associated DTOs define the structure and validation rules for session data. Tests verify session creation, validation, and revocation behavior.

src/domain/session · high confidence

Introduce standard HTTP response DTO

A new StandardHttpResponseDto has been added to the shared DTOs to provide a consistent structure for API responses, including a status code and generic data payload. This change standardizes the shape of HTTP responses across the application, ensuring uniform serialization and Swagger documentation for all endpoints.

src/shared/dto · high confidence

Introduce standardized API response structure and role-based API operation decorator

Users will see a consistent API response structure across endpoints, with success responses including a 'data' field and error responses including 'message' and 'error' fields. Additionally, the new @ApiOperationWithRoles decorator allows developers to easily associate specific user roles with API operations, improving security and documentation clarity.

src/shared/decorator · high confidence

Introduce structured configuration management and email service integration

The application now uses a formalized configuration system with a Zod-based schema (config-schema.ts) that validates environment variables for core settings, Redis, caching, rate limiting, and authentication. This includes new configuration keys for JWT secrets, token expiration, and email settings. The config module (config.module.ts) wires up dedicated configuration services (e.g., AuthenticationConfigService, EmailConfigService, TokenConfigService) and exports them for use across the application. Additionally, a new MailModule is introduced to support email functionality, aligning with the added EMAIL\_FROM configuration.

src/infrastructure/config · high confidence

Introduce user domain model with role-based access and validation

The user domain has been expanded to include a new UserRoleEnum supporting three distinct roles: USER, ADMIN, and DEVELOper. The User entity now enforces strict validation on all fields (first name, last name, email, password, and the new verifiedAt timestamp) and exposes role-based access control via the AllStaffRoles constant. This change allows the system to distinguish between standard users, administrators, and developers, with corresponding validation rules and event emissions for each field update.

src/domain/user · high confidence

Introduce v1 authentication module with comprehensive endpoint support

The v1 authentication module is introduced, wiring together controllers and command/query handlers for login, registration, logout, token refresh, and forgot-password flows. This establishes the core authentication endpoints and their underlying handlers, enabling users to authenticate, manage sessions, and recover access via password reset.

src/application/authentication/v1 · high confidence

Introduced domain events and authentication exceptions for the authentication flow

Added new domain event classes to the authentication module, including OnConfirmForgotPasswordEvent, OnForgotPasswordEvent, OnLoginUnverifiedEvent, OnLoginEvent, OnRegisterEvent, OnTokenRefreshEvent, and OnValidateCredentialsEvent, each carrying relevant context such as user, IP address, or session data. Additionally, new exception classes (AuthenticationNoEmailMatchException and AuthenticationPasswordIncorrectException) were introduced to handle specific authentication failures, extending NestJS's BadRequestException to provide clear error messaging for credential and email match issues.

src/domain/authentication · medium confidence

Introduced modular health check structure with V1 support

Added a new NestJS module at src/application/health/health.module.ts that imports the V1 health implementation, establishing a modular structure for health checks. This change enables the application to expose health check endpoints, likely supporting both legacy and new V1 health check logic through the V1HealthModule import.

src/application/health · high confidence

Introduces base entity and value object classes with validation and DTO support

Added new base classes for domain modeling: an abstract Entity class that manages ID, creation, and update timestamps with automatic validation, and a ValueObject base class for immutable domain primitives. The Entity base includes DTO decorators for Swagger documentation and class-validator integration, while the ValueObject enforces validation on construction. Tests were added to verify entity construction, timestamp updates, and value object validation behavior.

src/domain/base · high confidence

New Token module for caching

A new TokenModule has been introduced in the infrastructure layer, importing JwtModule and V1TokenModule to support token caching functionality.

src/infrastructure/token · medium confidence

New V1 refresh token endpoint

A new V1 API endpoint for refreshing access tokens has been introduced. The change adds a dedicated command handler and HTTP controller at /authentication/refresh, which accepts a valid refresh token to issue a new access token. The response is standardized to return the new access token, and the implementation leverages the existing CQRS pattern with event publishing for token refresh tracking.

src/application/authentication/v1/commands/refresh · medium confidence

New V1 token management module for authentication flows

A new V1TokenModule has been introduced to manage token generation and verification for access, refresh, reset password, and verification purposes. This module registers command handlers for generating access, refresh, reset password, and verification tokens, as well as query handlers for verifying reset password and verification tokens, centralizing the infrastructure for these specific token types.

src/infrastructure/token/v1 · high confidence

New generic exception classes for common error states

The application now includes five new, reusable exception classes in the shared exceptions module: GenericAlreadyExistsException, GenericInternalValidationException, GenericNoPermissionException, GenericNotFoundException, and GenericUnauthenticatedException. Each extends a corresponding NestJS built-in exception (ConflictException, InternalServerErrorException, ForbiddenException, NotFoundException, and UnauthorizedException respectively) and provides a standardized error message that can be extended with a cause. This allows the rest of the application to throw these specific exceptions to handle common error scenarios consistently.

src/shared/exceptions · high confidence

New response serialization and user tracing interceptors

Added three new interceptors in the shared module: a standard response wrapper that wraps all HTTP responses in a consistent JSON structure, a role-based class serializer that filters response data based on the authenticated user's role, and an OpenTelemetry tracing interceptor that attaches user ID and email to spans for observability.

src/shared/interceptors · high confidence

New user registration endpoint with auto-verification support

A new V1 registration flow is introduced, exposing a POST /authentication/register endpoint that accepts user details and an optional IP address. The handler automatically sets a verification timestamp if the authentication configuration enables auto-verification, then creates the user and publishes a registration event. The controller enforces a rate limit of 10 requests per minute to mitigate brute-force attempts and returns a response indicating whether email verification is required.

src/application/authentication/v1/commands/register · high confidence

New user registration endpoint with request and response DTOs

A new user registration flow is introduced via the v1 authentication API. The request payload now requires first name, last name, email, and password, validated through a combined DTO. The registration response returns the newly created user object and a boolean indicating whether email verification is required.

src/application/authentication/v1/commands/register/dto · high confidence

New validation decorators for CUID and property equality

Added two new validation decorators to the shared library: IsCuid, which validates that a value is a valid CUID using the @paralleldrive/cuid2 package, and IsEqualToProperty, which ensures a field matches the value of another specified property. These decorators allow developers to enforce specific data integrity rules directly on class properties.

src/shared/decorator/validation · high confidence

Behavioural changes

Add UserAlreadyVerifiedException for duplicate verification attempts

A new exception class, UserAlreadyVerifiedException, has been introduced in the user domain to handle cases where a user attempts to verify an account that is already verified. This change improves error handling by providing a specific, typed exception that extends NestJS's ForbiddenException, ensuring that duplicate verification attempts are caught and handled appropriately within the application's domain logic.

src/domain/user/exceptions · high confidence

Centralized configuration services for authentication, caching, and tokens

The application now uses dedicated configuration services to manage environment-specific settings. New services have been introduced to handle authentication parameters (including IP strictness and auto-verify flags), JWT and access/refresh token secrets and expiration times, cache and Redis connection details, email sender addresses, throttling limits, and general application metadata. These services abstract environment variable access, allowing the rest of the application to retrieve configuration values in a structured, type-safe manner.

src/infrastructure/config/configs · high confidence

Configure pre-commit hooks for linting, type-checking, and testing

The project now enforces code quality and correctness before each commit. When a commit is made, the system automatically runs lint-staged to check staged files, performs a full type-check, and executes the test suite. This ensures that only valid, tested code is committed to the repository.

.husky · high confidence

Introduce modular Mailer infrastructure with mock adapter

The mailer subsystem has been refactored into a modular structure, introducing a \MailerPort\ interface that defines \sendEmail\ and \sendEmails\ methods. A \MockMailerService\ implementation is provided for testing or non-production environments, which logs email details instead of sending them. The module exports the mailer provider globally, allowing other parts of the application to inject the mailer dependency.

src/infrastructure/mailer · high confidence

Introduce modular application structure with OpenTelemetry, CQRS, and throttling

The application module now integrates OpenTelemetry for distributed tracing, implements CQRS for command/query separation, and adds request throttling. It also registers standard response and user-tracing interceptors, alongside modules for authentication, sessions, verification, and email (MailerModule).

src/application · high confidence

Introduce modular authentication structure with event-driven handlers

The authentication module has been restructured to explicitly register event handlers for user registration and login success scenarios, alongside JWT and passport-based authentication strategies. This change introduces a more modular approach to handling authentication events and strategies within the application.

src/application/authentication · medium confidence

Introduce structured login endpoint returning access and refresh tokens

The login flow now returns a standardized response containing both an access token and a refresh token. The new \V1LoginResponseDto\ exposes these two string fields, and the \V1LoginController\ is configured to return this structured payload rather than a raw token string. This change affects the authentication endpoint's response format, providing clients with both tokens in a single, predictable object.

src/application/authentication/v1/commands/login · high confidence

Introduce structured token payload types and generation events

The token domain now uses a shared \BaseTokenPayload\ interface with a \type\ discriminator, alongside specific payload types for access, refresh, verification, and reset-password tokens. Corresponding domain events (\OnAccessTokenGeneratedEvent\, \OnRefreshTokenGeneratedEvent\, \OnResetPasswordTokenGeneratedEvent\, \OnVerificationTokenGeneratedEvent\) are added to capture token generation details, including user, session, and IP where applicable.

src/domain/token · high confidence

JWT module refactored to use global configuration

The JWT module has been refactored to be globally available, ensuring that all parts of the application can access JWT services without explicit imports. This change simplifies authentication and session handling across the application.

src/infrastructure/jwt · high confidence

Restructured Ping application module

The Ping application module has been restructured to import the new V1PingModule and register the PingRanHandler as an event handler, indicating a shift in how the ping functionality is composed within the application layer.

src/application/ping · medium confidence

Stronger typing for authenticated request context

The types for authenticated requests have been strengthened. A new \RequestWithUser\ interface now requires both \user\ and \session\ properties, whereas previously the \user\ field on the standard Express \Request\ was optional. This ensures that code accessing \req.user\ or \req.session\ can do so without null-checks, reflecting the expectation that these fields are always present when authentication is active.

src/types · medium confidence

Test coverage

Added mock session repository for testing; Added test utility for generating mock users and sessions; Added unit tests for the PingRanHandler.

Dependencies

Initial dependency setup for the enterprise NestJS framework

The project's \package.json\ and \pnpm-lock.yaml\ have been added, establishing the full set of runtime and development dependencies for the NestJS application. This includes core libraries such as \@nestjs/\\ (v10.3.9), \@opentelemetry/\\ for observability, \ioredis\ and \cache-manager-redis-yet\ for caching, and various utility packages like \zod\, \class-validator\, and \helmet\. Development tools like \jest\, \biome\, and \husky\ are also configured.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 56 → 56 (+0.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 90 → 92 (+2.2)
  • Architecture 57 → 57 (+0.1)
  • Maturity 60 → 58 (-2.5)
  • Readiness 48 → 50 (+1.9)
  • Security 62 → 68 (+5.7)

Resolved (59)

  • Change coupling: access-token.guard.ts ↔ access-token.strategy.ts (src/application/authentication/strategies/access-token/access-token.guard.ts)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 39 more

New (83)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • End-of-life runtime: Node.js 20
  • High CVE: [CVE redacted] (pnpm-lock.yaml)
  • High CVE: [CVE redacted] (pnpm-lock.yaml)
  • High CVE: [CVE redacted] (pnpm-lock.yaml)
  • High CVE: [CVE redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 63 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

TheGoatedDev/EnterpriseNest was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2051ccf281153b716cca82c9a99189036808b3f0 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.