Skip to content
CAI
Software that uses CAICheck a score

Azure/reddog-solutions

56.9

Adequate · 21 September 2026

4.3k

lines of production code

Java

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a microservices-based application comprising distinct services for accounting, gateway, loyalty, order processing, and virtual entities. It has been modernized to Spring Boot 3.3, migrating from Netflix Eureka to a generic Spring Cloud discovery client and replacing Sleuth with Micrometer Tracing for distributed observability. The infrastructure configuration has been simplified by removing Azure Key Vault dependencies in favor of local environment variables and standardizing the development profile.

Behavioural changes

Renames Azure Key Vault endpoint environment variable

The deployment script now exports the Azure Key Vault endpoint as AZUREKEYVAULTENDPOINT instead of AZURE\_KEY\_VAULT\_ENDPOINT in both the local variables file and the Kubernetes ConfigMap, ensuring consistency with the expected configuration key name.

scripts · high confidence

Service discovery migration and configuration simplification

All services (accounting, gateway, loyalty, makeline, order, virtual-customers, virtual-worker) now use the standard Spring Cloud \EnableDiscoveryClient\ annotation instead of the Netflix Eureka-specific \EnableEurekaClient\, making them compatible with any Spring Cloud discovery implementation. Additionally, the \key-vault\ and \configserver\ Spring profiles have been removed from the main \application.yaml\ files across all services, simplifying the configuration to rely solely on the \dev\ profile and local environment variables. In the order-service, the Hibernate dialect was updated from \MySQL5Dialect\ to \MySQLDialect\ in the production configuration, and Java EE validation/persistence imports (\javax.\\) were migrated to Jakarta EE (\jakarta.\\) namespaces.

(repo-wide) · high confidence

Switches service discovery from Eureka to generic discovery client

The local gateway now uses the generic Spring Cloud discovery client instead of the Eureka-specific client. This change allows the gateway to register with and discover services via any supported service registry, rather than being locked to Eureka.

ancillary/local-gateway · high confidence

Dependencies

Upgrade to Spring Boot 3.3 and migrate distributed tracing to Micrometer

This update upgrades the Spring Boot parent to version 3.3.0 and the Spring Cloud BOM to 2023.0.2 across all service POMs. It replaces the deprecated Spring Cloud Sleuth with Micrometer Tracing (using the OpenTelemetry bridge) and adds the OpenTelemetry Zipkin exporter for distributed tracing. Additionally, several supporting libraries are updated, including Spring Cloud Azure (4.7.0 to 5.13.0), MapStruct (1.5.2 to 1.5.5), SpringDoc OpenAPI (1.6.11 to 1.8.0), Lombok (1.18.24 to 1.18.32), and the Application Insights agent (3.4.6 to 3.5.3).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 51 → 57 (+5.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 98 (-1.4)
  • Architecture 100 → 91 (-8.9)
  • Maturity 71 → 71 (+0.0)
  • Readiness 34 → 41 (+6.8)
  • Security 48 → 61 (+12.8)

Resolved (68)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (generative-ai/az-huggingface/requirements.txt)
  • Critical CVE: [GHSA redacted] (generative-ai/az-huggingface/requirements.txt)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (12 lines × 5) (accounting-service/src/main/java/com/microsoft/gbb/reddog/accountingservice/model/OrderSummary.java)
  • Duplicated block (12 lines × 7) (accounting-service/src/main/java/com/microsoft/gbb/reddog/accountingservice/dto/OrderSummaryDto.java)
  • Duplicated block (6 lines × 3) (accounting-service/src/main/java/com/microsoft/gbb/reddog/accountingservice/config/KafkaTopicConfiguration.java)
  • Duplicated block (7 lines × 2) (loyalty-service/src/main/java/com/microsoft/gbb/reddog/loyaltyservice/config/RedisConfig.java)
  • High CVE: [GHSA redacted] (generative-ai/az-huggingface/requirements.txt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 48 more

New (343)

  • Critical CVE: [GHSA redacted] (generative-ai/az-huggingface/requirements.txt)
  • Critical CVE: [GHSA redacted] (generative-ai/az-huggingface/requirements.txt)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Duplicated block (13 lines × 12) (accounting-service/src/main/java/com/microsoft/gbb/reddog/accountingservice/dto/OrderSummaryDto.java)
  • Duplicated block (44 lines × 2) (order-service/src/main/java/com/microsoft/gbb/reddog/orderservice/dto/ProductDto.java)
  • Duplicated block (44 lines × 5) (accounting-service/src/main/java/com/microsoft/gbb/reddog/accountingservice/model/OrderItemSummary.java)
  • Duplicated block (52 lines × 2) (order-service/src/main/java/com/microsoft/gbb/reddog/orderservice/dto/CustomerOrderDto.java)
  • Duplicated block (56 lines × 2) (accounting-service/src/main/java/com/microsoft/gbb/reddog/accountingservice/config/CosmosDbConfig.java)
  • Duplicated block (7 lines × 3) (accounting-service/src/main/java/com/microsoft/gbb/reddog/accountingservice/config/KafkaTopicConfiguration.java)
  • Duplicated block (8 lines × 2) (loyalty-service/src/main/java/com/microsoft/gbb/reddog/loyaltyservice/config/RedisConfig.java)
  • High CVE: [GHSA redacted] (generative-ai/az-huggingface/requirements.txt)
  • High IaC: WD-COMPOSE-0002 (accounting-service/docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (accounting-service/docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-DOCKER-0006 (accounting-service/Dockerfile-multi-stage)
  • High IaC: WD-DOCKER-0006 (gateway-service/Dockerfile-multi-stage)
  • High IaC: WD-DOCKER-0006 (loyalty-service/Dockerfile-multi-stage)
  • High IaC: WD-DOCKER-0006 (receipt-generation-service/Dockerfile-multi-stage)
  • High IaC: WD-DOCKER-0006 (virtual-customers/Dockerfile-multi-stage)
  • …and 323 more

Changes since last survey

  • 2 commits — 2 feature/other, 0 fixes

By area

  • (repo) — 1 commit
  • .github/workflows — 1 commit

Notable commits

  • change: Merge pull request #62 from danfiedler-msft/danfiedler/pin-actions
  • change: Pin GitHub Actions to full-length commit SHAs

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Azure/reddog-solutions was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e4fcc765c9405643cae4ad947157c89b302e7b02 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.