Skip to content
CAI
Software that uses CAICheck a score

typicode/json-server

62.9

Adequate · 25 September 2026

762

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Introduce new query filtering and data normalization capabilities

The application now supports advanced query filtering via a new \\_where\ parameter that accepts a JSON object for complex conditions (e.g., \eq\, \gt\, \in\, \contains\). The \NormalizedAdapter\ automatically ensures every item has a string \id\ and auto-inserts a default \$schema\ path when reading the database file. Additionally, the system now returns JSON-formatted 404 and 400 error responses instead of plain text, and the CLI automatically creates an empty JSON object if the data file is empty.

src · high confidence

Major v1.0 release with TypeScript, JSON Schema, and new query syntax

The project has been rewritten in TypeScript with a new build system, introducing a JSON Schema (schema.json) for data validation and a new CLI interface that no longer requires the --file flag. The legacy server.js entry point has been removed, and the README has been updated to reflect the beta v1 status, new query capabilities (e.g., \_where, \_sort, \_embed), and sponsorship sections.

(repo-wide) · high confidence

Removals

Removal of legacy CLI entry point

The bin/cli.js file, which previously served as the Node.js CLI entry point using the commander library, has been removed. This eliminates the command-line interface for loading databases from files or URLs and starting the server via the CLI.

bin · high confidence

Behavioural changes

Configure pre-commit hook to run tests with pnpm

A new pre-commit hook has been added to the .husky directory, configured to execute tests using pnpm. This ensures that the test suite is automatically run before each commit, with the specific choice of pnpm as the package manager for the test command.

.husky · high confidence

Redesigned index page with system dark mode support

The homepage now features a complete visual overhaul with a cleaner, sans-serif font stack and indigo hover states. It also supports system dark mode, automatically adapting colors for light and dark themes using CSS variables.

views · high confidence

Removal of default public assets

The default landing page (public/index.html) and its associated stylesheet (public/stylesheets/style.css) have been removed. Users who relied on the built-in welcome page and styling will no longer see these assets served automatically.

public · high confidence

Removal of legacy utility modules

The \utils\ directory has been cleared of three utility modules: \db-mixins.js\ (which provided database CRUD operations like create, update, and remove), \logger.js\ (which configured the logan logging library), and \utils.js\ (which provided a toNative type conversion helper). These files have been deleted, indicating a refactoring or cleanup of the codebase's utility layer.

utils · high confidence

Removed read-only and read-write route handlers

The application no longer exposes the previous read-only and read-write route definitions. Specifically, the files \routes/read-only.js\ and \routes/read-write.js\ have been deleted, removing the associated endpoints for listing, showing, creating, updating, and destroying resources via JSONP responses.

routes · high confidence

Test coverage

Added sample database fixtures for testing; Removed obsolete test files.

Dependencies

Major dependency overhaul and build system modernization

The project has been significantly modernized by replacing the legacy Express and Underscore dependencies with the modern @tinyhttp suite (including @tinyhttp/app, cors, and logger) and other updated libraries like lowdb 7.0.1 and chokidar 5.0.0. This change is accompanied by a shift to an ES module-based build system using TypeScript, which introduces new dev dependencies for linting and formatting (oxlint, oxfmt) and enforces a minimum Node.js version of 22.12.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 63 (+14.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 91 → 91 (+0.2)
  • Architecture 69 (new)
  • Maturity 55 → 59 (+3.5)
  • Readiness 33 → 56 (+23.5)
  • Security 63 → 90 (+26.3)

Resolved (15)

  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No artifact signing
  • No automated tests
  • No build provenance
  • No exposed public API
  • No tests found
  • Test reliability not included

New (18)

  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/matches-where.ts (src/matches-where.ts)
  • No ADRs found
  • No dependency advisory monitoring
  • Outdated (npm): @tinyhttp/app
  • Outdated (npm): chalk
  • Outdated (npm): dot-prop
  • Outdated (npm): eta
  • Outdated (npm): milliparsec
  • Repeated repair: src/app.ts (src/app.ts)
  • matches-where.matchesWhere (cognitive 122) (src/matches-where.ts)
  • matches-where.matchesWhere (cyclomatic 39) (src/matches-where.ts)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

typicode/json-server was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 89a34a44b7a6a5311dc84f3b8a1b8b45c0905aea — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.