acronis/go-cti
68.7
Adequate · 21 September 2026
9k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based toolkit for managing Cross-domain Typed Identifiers (CTI) metadata. It provides libraries and a CLI to parse, validate, and package CTI entities from various sources like RAMLx and JSON Schema. The system also handles dependency resolution, archive creation, and compatibility checking for CTI packages.
How it got here
2024 — CTI parsing and package management
13 changes.
This period focused on implementing the core infrastructure for Cross-domain Typed Identifiers (CTI), including a new parsing library, metadata validation framework, and package management system. The work established the \metadata\ and \cmd/cti\ modules to handle entity management, dependency resolution, and CLI tooling for package operations.
2025 — CTI metadata collection and compatibility checking
4 changes.
This period focused on establishing the infrastructure for collecting and validating CTI metadata. The work introduced new collectors for parsing CTI and RAMLx sources, alongside a typed JSON Schema handler for schema merging. Additionally, a compatibility checker was implemented to validate package compatibility and detect breaking changes.
Features
Added CTI and scalar type definitions to the RAMLx specification
The RAMLx metadata package now includes the \spec\_v1\ directory containing \cti.raml\ and \scalar.raml\. This adds support for Common Type Infrastructure (CTI) identifiers, including new annotation types such as \resilient\, \access\, \access\_field\, \cti\, \id\, \final\, \reference\, \schema\, \embed\, \overridable\, \asset\, and \l10n\. It also introduces the \CTI\ and \CTIWildcard\ types for managing entity references and the \CTIAttribute\ type for accessing object properties. Additionally, a comprehensive set of scalar types is provided, including string lengths (e.g., \string1024\), integer types (\uint8\ to \int64\), floating-point numbers (\float8\ to \float64\), and other primitives like \byte\, \rune\, and \True\.
metadata/ramlx · high confidence
Introduce CLI command structure and package management utilities
The \cmd/cti/internal\ directory now contains the foundational structure for the CLI, introducing a suite of command handlers including \init\, \pack\, \pkg\ (with \get\, \download\, \tidy\ subcommands), \sync\, and \validate\. This change adds core utility functions for error handling (\WrapError\), working directory management, and package parsing, while establishing the command-line interface for package management and validation workflows.
cmd/cti/internal · high confidence
Introduce CTI metadata collector for parsing CTI entities
Added a new CTI metadata collector that parses and registers CTI type and instance entities from YAML fragments. The collector reads the first line of each fragment to determine whether it is a CTI Type or Instance, unmarshals the content into the appropriate metadata entity, and adds it to the registry. This enables the system to collect and manage CTI metadata as package entities.
metadata/collector/ctimetadata · high confidence
Introduce CTI metadata library with entity management, validation, and annotation collection
The metadata package now provides a comprehensive library for parsing, validating, and managing CTI (Cross-domain Typed Identifiers) entities and packages. This includes core types for entity types and instances, an annotation collector for JSON Schema traversal, an attribute selector for navigating nested structures, and a registry for storing and indexing entities. The library supports custom validation rules, access modifiers, and legacy source map formats, enabling users to work with CTI metadata in a predictable, type-safe manner.
metadata · high confidence
Introduce CTI metadata validation framework
Added a new metadata validator in the \metadata/validator\ package that enforces structural and semantic rules on CTI metadata entities and instances. The validator supports registering type and instance validation hooks, aggregates rules by matching CTI expressions, and reports issues with severity levels (error, warning, info). Tests confirm that validation hooks are correctly registered and that invalid CTI expressions are properly rejected.
metadata/validator · high confidence
Introduce CTI package metadata parsing and validation
Added the \metadata/ctipackage\ package to handle CTI package metadata, including an \Index\ struct that tracks APIs, entities, assets, and dependencies, along with an \IndexLock\ for tracking dependency hashes. The \Package\ type now supports initialization, reading, and parsing of CTI packages, including resolving dependencies and validating package IDs and dependency names. Tests have been added for index parsing, cloning, saving, and validation.
metadata/ctipackage · high confidence
Introduce Cross-domain Typed Identifiers (CTI) parsing library and CLI tool
The project now provides a Go library for parsing and validating Cross-domain Typed Identifiers (CTI) expressions, including support for wildcards, inheritance, and dynamic parameters. This includes the core \parser.go\ and \expression.go\ implementations, along with comprehensive unit and benchmark tests. Additionally, a CLI tool (\cti\) is introduced to manage CTI packages, supporting commands for initialization, package retrieval, validation, and bundling.
(repo-wide) · high confidence
Introduce RAMLx metadata collector for CTI schema processing
Added a new RAMLx collector that parses RAML 1.0 libraries to extract CTI metadata types, handling type unwrapping, implicit schema insertion, and trait merging. The collector processes custom domain properties, validates traits, and registers entities in the metadata registry. This enables the system to collect and structure metadata from RAMLx sources, supporting features like final/resilient/access modifiers and source map tracking.
metadata/collector/ramlx, metadata/transformer · high confidence
Introduce archiver abstraction with tar.gz and ZIP implementations
Added a new \metadata/archiver\ package that defines an \Archiver\ interface for creating archives, along with concrete implementations for \.tar.gz\ and \.zip\ formats. This provides a unified way to write files, bytes, and directories into archives, supporting directory walking and file exclusion via the \SkipFile\ and \SkipDir\ error markers. The \tgzwriter\ and \zippacker\ packages implement this interface, handling file metadata, symlink warnings, and recursive directory packing while preventing self-referential archiving.
metadata/archiver · high confidence
Introduce metadata collector interface and base implementation
A new \Collector\ interface and \BaseCollector\ struct have been added to the \metadata/collector\ package. This introduces a mechanism to collect metadata from a source and return a map of collected entities, utilizing a \CTIParser\ and a \MetadataRegistry\ to manage local and package-declared entities.
metadata/collector · high confidence
Introduce packer module for building CTI packages
Added the metadata/packer module, which provides a configurable Packer struct to assemble CTI packages. The packer supports optional source inclusion, custom file exclusion logic, and extensible annotation handlers to process entity data during the packaging process.
metadata/packer · high confidence
Introduce pacman package manager for dependency resolution and installation
The pacman package introduces a new package manager responsible for resolving, downloading, and installing dependencies. It manages a local cache of packages and sources, handling integrity checks and link patching. The implementation includes functions to download dependencies, validate source and package integrity, and install dependencies from either an index or an index-lock file. Tests and mock storage are also added to support the new functionality.
metadata/pacman · high confidence
Introduce typed JSON Schema handling and schema merging for CTI metadata
The metadata/jsonschema package now provides a typed Go representation of JSON Schema (JSONSchemaCTI) that maps CTI-specific extension properties (such as x-cti.access, x-cti.final, and x-cti.id) to Go structs. This change introduces a schema merging mechanism that applies inheritance rules, allowing child schemas to inherit and override properties from parent schemas. The implementation includes a pre-compiled Draft-07 meta-schema for validation and utility functions for deep copying and reference resolution, enabling more robust handling of complex metadata structures.
metadata/jsonschema · high confidence
Introduces new file system utilities for handling archives, checksums, and directory operations
The metadata/filesys package now provides a suite of new file system utilities. This includes secure extraction functions for ZIP and TAR archives (SecureUnzip, SecureUntar) with path traversal protection and file size limits, as well as helper functions for reading and writing JSON files, computing file and directory checksums using XXH3, and performing directory copy/move operations. These additions expand the capabilities for interacting with the local file system, particularly for safely extracting and managing archive files and computing hashes.
metadata/filesys · high confidence
New compatibility checker for CTI packages
A new compatibility checking system has been introduced in the metadata/compatibility package. This system allows users to validate compatibility between two CTI packages by comparing entities, their schemas, traits, values, and annotations. The checker identifies removed, new, and modified entities, and reports errors, warnings, or informational messages about compatibility issues. This enables users to detect breaking changes between package versions before deployment.
metadata/compatibility · high confidence
Behavioural changes
CLI entry point and command structure restructured
The \cmd/cti\ package was restructured to serve as the new entry point for the CLI, integrating logging setup, the root command, and all subcommands (init, pack, validate, etc.) into a single cohesive structure. This change consolidates the CLI's command registration and error handling, ensuring that tracebacks are properly captured and logged with the \go-stacktrace\ library.
cmd/cti · high confidence
Dependencies
Updated project dependencies and module structure
The project's Go module files (go.mod and go.sum) have been updated to align cross-module dependency versions. This includes updating the go-raml library to v2.0.10 in the metadata module, bumping go-cti to v1.0.0, and updating go-stacktrace to v0.4.0. Additionally, the cmd/cti module has been established with its own dependencies, including go-raml v2.0.2 and go-cti v1.0.0.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 62 → 69 (+6.7)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 92 (new)
- Architecture 100 → 100 (-0.1)
- Maturity 56 → 56 (+0.0)
- Readiness 57 → 72 (+15.1)
- Security 69 → 81 (+12.0)
Resolved (20)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (cmd/cti/go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2024-2598 (go.mod)
- Medium CVE: GO-2024-3105 (cmd/cti/go.mod)
- Medium CVE: GO-2026-5024 (cmd/cti/go.mod)
- Medium CVE: GO-2026-5970 (cmd/cti/go.mod)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
- complexity unreadable for .go — churn × complexity hotspots could not be measured
New (92)
- Documentation: no installation or build instructions (README.md)
- FixmeComment (metadata/collector/ramlx/collector.go)
- FixmeComment (metadata/ctipackage/parser.go)
- FixmeComment (metadata/ctipackage/parser.go)
- FixmeComment (metadata/ctipackage/parser.go)
- High CVE: [GHSA redacted] (cmd/cti/go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2024-2598 (go.mod)
- Medium CVE: GO-2024-3105 (cmd/cti/go.mod)
- Medium CVE: GO-2026-5024 (cmd/cti/go.mod)
- …and 72 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
acronis/go-cti was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 8e1bc590c53c6b6cb1be696b87011c5ccd3729be — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.