mrkeyoor.com_
Tue 29 Sept 20:26 UTC
Webevaluationupdated 02 Sept 2026

nest review

NestJS is a TypeScript-first framework for building Node.js servers with a prescribed application structure. It supplies modules, dependency injection, controllers, and adapters for common server work, so a growing backend does not have to invent its own architecture.

+28stars / 7d
Verdict

Our August 24 NestJS checkout installed 1,322 packages and passed all 2,739 tests, but npm audit found 38 known vulnerabilities, so adoption should include dependency triage. Use it when a TypeScript backend is large enough that shared structure saves more time than framework ceremony costs. For a small API, direct Express or Fastify code is easier to see and change.

We ran it

Lab card: what happened when we ran nestScreenshot of nest (nestjs.com)
Install✓ · 45s1322 packages · 614 MB
Build✓ · 17s
Tests✓ · 41s2739 passed · 0 failed of 2739 (vitest)
Known vulns383 critical · 20 high · 11 moderate · 4 low (npm audit)
Repo2297 files~133,426 lines of source · 5.7 MB · 1 CI workflows

Answers from our run

Does nest build from source?

Dependencies installed in 45 seconds (1322 packages), and the build succeeded in 17 seconds. We cloned commit 4f78332 into a clean Debian container with 3 CPUs and no project-specific setup.

Do nest's tests pass?

Yes: 2739 of 2739 passed when we ran the project's own test command (vitest). Some failures need services or credentials a bare container does not have.

Does nest have known vulnerabilities in its dependencies?

npm audit flagged 38 known advisories in the dependency tree, including 3 critical at the time of our run.

Who should not use nest?

Small services where a router and a few functions are enough: Nest's generated project starts with a module, controller, service, bootstrap file, and test before business code grows.

What are the alternatives to nest?

Fastify, Express, AdonisJS. Our August 24 NestJS checkout installed 1,322 packages and passed all 2,739 tests, but npm audit found 38 known vulnerabilities, so adoption should include dependency triage.

Setup4/545-second install and clean build, with 614 MB of dependencies
Docs5/5The guide explains core concepts, adapters, testing, and integrations
Community5/5More than 76,500 stars, a September 2 push, and current issue activity
Maturity5/5v12.0.0 shipped August 27; our checkout passed all 2,739 tests

Discussed on

  1. hnShow HN: NestJS – A Progressive Node.js Framework4 points
  2. hnNestJS 84 points
  3. hnNest – A TypeScript back end framework built on top of Express4 points

Who it’s for

TypeScript teams building APIs or services that need the same conventions across many developers.
Backend groups that want dependency injection, decorators, testing seams, and documented patterns in one framework.
Organizations using Express or Fastify underneath but wanting a consistent application layer above either one.
Teams prepared to learn Nest's module and provider model before shipping features.

Who it’s NOT for

Small services where a router and a few functions are enough: Nest's generated project starts with a module, controller, service, bootstrap file, and test before business code grows.
Teams that reject Angular-style dependency injection and class decorators: the README says Nest's architecture is heavily inspired by Angular.
Kafka services that cannot accept an unsettled client dependency: issue 13223 about the KafkaJS transport was still open with 63 comments and activity on August 28, 2026.
Upload services that need documented streaming defaults: issue 13158 reports that the documented upload path produces a Buffer and can hold the whole file in memory.
Organizations whose policy blocks a checkout with known audit findings: our npm audit found 38 vulnerabilities, including 3 critical and 20 high, which need triage before adoption.

Setup reality

Our sandbox installed 1,322 npm packages in 45 seconds and used 614 MB. The build passed in 17 seconds, then Vitest passed all 2,739 tests in 41 seconds. npm audit reported 38 known vulnerabilities: 3 critical, 20 high, 11 moderate, and 4 low.

NestJS v12 requires Node.js v20.19+ or v22.12+ and no credentials for a basic HTTP app. Real applications add their own database, authentication, queue, GraphQL, or messaging configuration. Contributors install the whole npm workspace, while application teams can install only the Nest packages and platform adapter they use.

Express is the default HTTP platform; Fastify requires its Nest adapter, and platform-specific middleware does not become portable by choosing Nest. The repository had no Dockerfile, so container policy is yours. Its 2,297-file monorepo also asks more of contributors than the short CLI quick start suggests.

NestJS pros and cons start with structure versus ceremony

NestJS gives a Node.js backend a house style, and its starter makes the tradeoff visible in 5 files: a controller, its test, a module, a service, and main.ts. Controllers receive requests, providers contain application logic, modules declare boundaries, and dependency injection connects the pieces. Teams get a shared vocabulary for services and tests, while developers give up some freedom to arrange code however they like.

The README says the architecture is heavily inspired by Angular. That can feel excessive beside a small Express router, but the structure starts earning its keep when several people must find the same kinds of code, replace providers in tests, or apply guards and validation consistently. NestJS v12 requires Node.js v20.19+ or v22.12+. JavaScript remains supported, although the documentation and programming model favor TypeScript.

NestJS v12.0.0 uses Express by default; Fastify still changes platform details

NestJS v12.0.0 does not replace the HTTP engine. The default @nestjs/platform-express package runs Express, while @nestjs/platform-fastify selects Fastify. NestJS can carry most application logic across those adapters and reuse its building blocks for WebSockets, microservice transports, GraphQL, scheduled work, and command-line applications. Code that reaches into a platform API remains tied to the selected adapter.

Express middleware and Fastify plugins have different interfaces, so an adapter switch needs testing around uploads, authentication, error handling, and every platform-specific package. Issue 13158 is a warning for file-heavy services: the reporter says the documented upload decorator path returns a Buffer, which can place the full upload in memory. The issue had 14 comments and remained open after its July 28, 2026 update.

What happened when we ran it

Our sandbox installed 1,322 npm packages in 45 seconds, occupying 614 MB on disk. The TypeScript build completed in 17 seconds. Vitest then passed all 2,739 tests in 41 seconds, with 0 failures. The checkout at commit 4f78332 contained 2,297 files and about 133,426 lines of source.

The clean test result does not settle dependency risk. npm audit found 38 known vulnerabilities in the installed tree: 3 critical, 20 high, 11 moderate, and 4 low. The measurement does not show which packages reach a deployed NestJS application, because the repository workspace includes development tools and optional integrations. A team should inspect the audit paths, determine production exposure, and record any accepted findings.

Our test method ran the checkout in a Node 22 container with 3 CPUs and 8 GB of memory. The scan found 1 CI workflow, no Dockerfile, no top-level tests directory, and npm workspaces. Vitest found the 2,739 tests elsewhere, so the absent directory is only a layout signal. The missing Dockerfile is more practical: application owners must choose an image, process manager, health check, and secret strategy.

A NestJS app starts smaller than our 1,322-package contributor install

Our 1,322-package measurement covers the NestJS monorepo, not an application created by the CLI. The quick start installs the CLI, runs nest new, and starts the generated server. A basic HTTP service needs no external credentials. Databases, queues, authentication, GraphQL, and message brokers arrive through whichever modules the application chooses, each with its own configuration and operating cost.

Contributors see the larger side of NestJS: our install pulled 1,322 packages before a 17-second build. A framework wrapper also leaves transport choices with the operator. Open issue 13223 questions the Kafka transport's KafkaJS dependency and had 63 comments after an August 28, 2026 update. A common NestJS interface cannot remove the maintenance status or behavior of the client underneath.

NestJS v12.0.0 adds ESM packages and an upgrade command

NestJS v12.0.0 shipped on August 27, 2026 with ESM-ready packages, Standard Schema support, a rebuilt CLI, and the new @nestjs/observe SDK. Existing CommonJS applications can keep working, while nest upgrade updates Nest packages and handles listed mechanical migrations. The release requires Node.js v20.19+ or v22.12+, and its upgrade command refuses older versions.

GitHub recorded 76,556 stars, 33 open issues and pull requests combined, and a September 2, 2026 push when fetched. That activity does not make every integration safe. Old open requests around uploads, Kafka, and WebSocket behavior still deserve a check when they touch a workload. Pin the packages an application uses and test those exact adapters during a v12 upgrade.

NestJS pays off when consistency already hurts

The 2,739 passing tests support NestJS as a company standard for a substantial TypeScript backend, while the 614 MB contributor install and 38 audit findings make it a framework to govern. Modules and dependency injection help when coordination across people or services already costs time. A five-route service rarely needs that machinery.

Express or Fastify will usually be easier to understand for a small service because the request path remains in ordinary functions and middleware. AdonisJS is the closer comparison when a team wants an opinionated TypeScript application stack rather than NestJS's broad server architecture. Choose NestJS for consistent structure, then budget time for adapter behavior, dependency review, and major-version migrations.

Alternatives

ProjectWhat it isPick it when
Fastify gh↗A focused Node.js web framework with plugins, schemas, and less application-level structure.pick this instead when you want an HTTP foundation and prefer to design your own application architecture.
Express gh↗The minimalist Node.js framework that Nest uses as its default HTTP platform.pick this instead when direct middleware and routing are enough, and a dependency injection layer would add ceremony.
AdonisJSA TypeScript web framework with an integrated application stack and its own conventions.pick this instead when you want more first-party web application pieces gathered in one ecosystem.

Sources

  1. Nest repository and README
  2. Nest first steps documentation
  3. NestJS v12.0.0 release
  4. KafkaJS transport discussion
  5. File upload buffering issue

More web reviews

vinext · robinhood-meme-token-stock-launchpad · kool-brushez · pure · shadcn-admin · m3e-canvas · the whole board →