Repository validation

Vendure

A TypeScript commerce platform with NestJS backend packages, frontend packages, plugins, and shared libraries.

Independent analysis of a public repository. This project is not affiliated with or endorsed by ArchPilot. Product and project names are used only for identification.

See something inaccurate? Contact us.

What ArchPilot found

12 components, 8 mapped relationships.

ArchPilot modeled Vendure as a 12-component TypeScript monorepo spanning NestJS backend packages, Angular and React frontend packages, plugins, and shared libraries.

The run shows a strong 0.2.10 TypeScript monorepo result: complete dependency evidence, clear backend/frontend/library structure, and reviewable warnings without error-level findings.

Components
12

Source-backed architecture units

Relationships
8

Mapped module dependencies

Errors
0

Blocking validation findings

Warnings
84

Items for review, not confirmed defects

Dependency analysis
Established

Dependency analysis was established for the preserved 0.2.10 validation evidence.

Why it is useful

From repository shape to reviewable architecture signals.

The point is not to score open-source projects against each other. The point is to show how local validation turns repository structure into a model teams can inspect and govern.

Architecture inventory

ArchPilot identifies the major backend, frontend, plugin, and library structure as 12 architecture components.

Dependency evidence

Dependency analysis is established, so dependency conclusions have complete evidence for this run.

Review focus

Warnings point reviewers toward areas that deserve human interpretation.

Governance baseline

Generated contracts give teams a starting point for local validation and CI policy.

Findings

What deserves attention

74 normalized finding clusters

Findings below are grouped into areas so readers can see what is deterministic architecture evidence, what is a review signal, and what depends on governance scope.

Dependency hub

packages-core has eight declared and actual inbound dependencies.

Count
1
Interpretation
Confirmed architecture evidence
Rule
AP-DEP-009

Collection reads

Several ORM reads return collections without visible pagination evidence.

Count
10
Interpretation
Review signal
Rule
AP-DQR-003

Application services

Large services with many methods or collaborators are flagged for review.

Count
26
Interpretation
Review signal
Rule
AP-APP-005

Ownership boundaries

Some services and domain operations are large enough to deserve boundary review.

Count
40
Interpretation
Review signal
Rule
AP-DOM-003/AP-DOM-004

Transaction and decision context

Transaction-sensitive paths and ADR expectations provide governance context.

Count
7
Interpretation
Scope-dependent observation
Rule
AP-TXN-002/AP-TXN-003/AP-ADR-004

Confirmed architecture evidence

Core package is an architectural hub

The 0.2.10 run established dependency analysis and reported one AP-DEP finding.

Source
Architecture map

Review signal

Order service carries broad application responsibility

The architecture model identifies the major backend, frontend, plugin, and library structure without claiming unresolved authentication or database details as detected architecture.

Source
Architecture map

Warnings remain review signals

Warnings help reviewers choose inspection areas. They are not published as confirmed defects.

Scope
Human architecture review

How to interpret this validation

  • ArchPilot successfully established dependency analysis for this validation.
  • The architecture model identifies the major backend, frontend, plugin, and library structure. Unresolved authentication or database facts are not presented as detected architecture.
  • Warnings are not confirmed project defects. Many are heuristic review signals.
  • Scores describe conformance to the generated model and supported rules, not a ranking against other projects.
  • This is independent analysis of a public repository, not maintainer endorsement.

Reproduce and verify

Run from commit d4a324cee099 with ArchPilot 0.2.10.

View commit
Exact CLI commands
npx --yes @archpilotlabs/[email protected] init --yes
npx --yes @archpilotlabs/[email protected] validate --json
npx --yes @archpilotlabs/[email protected] map --json
npx --yes @archpilotlabs/[email protected] report --json
Repository provenance
Branch
master
Commit date
2026-08-21T22:00:49Z
Validation date
Sep 10, 2026
Package and configuration proof
Package
@archpilotlabs/archpilot@0.2.10
Integrity
sha512-2V0WfNnvZVS/ey7ndKkhvYBI2YqIkrNTwkFmpMdjkMrb2RQuN7uDYCsOW2dVDPOqyf2q86V3gnc38i2jENGQOg==
Config hash
66FFC2CD0F09BDD9073DF94DD8C4C75F4FAC75B333F69E14E486F87F72E15AD2
Artifact hashes
architecture.json
66FFC2CD0F09BDD9073DF94DD8C4C75F4FAC75B333F69E14E486F87F72E15AD2
validation-status.json
D5738E5E0C526EA772441FCF48383906ABEB24879D349B8213A584D482DD3811
architecture-map.json
7E56ABD5E5DC9DA1A0189AEF1DE5E039B5B13BFB6F9E71E431C6615B2138FC1C
architecture-review-report.json
94FD731021C4912FBC0FBDB9BE9B9C85132EFC2FCF119B859FD7633EEDB71237

Try it locally

Run the same workflow on your repository.

The extension and CLI validate architecture locally. ArchPilot Cloud brings those results together for shared history, policy workflows, cross-repository intelligence, and organization-wide governance.

Vendure Architecture Validation | ArchPilot