Skip to content
CAI
Software that uses CAICheck a score

bmf-san/go-clean-architecture-web-application-boilerplate

50.4

Weak · 21 September 2026

595

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Go-based web application built on a Clean Architecture, designed to manage users and their posts. It provides a complete backend stack that handles HTTP routing, database connectivity to MySQL, and structured logging. The system exposes controllers and repositories to interact with user and post data, supported by Dockerized development and production environments.

Features

Added infrastructure layer for environment, logging, routing, and database handling

The app/infrastructure directory now contains the concrete implementations for core application concerns. Environment variables are loaded from a .env file, with a fix to correctly parse values containing the '=' character. A new Logger implementation writes error and access logs to separate files and stdout. The router is configured using the Chi framework, mapping HTTP endpoints for users and posts to their respective controllers. Finally, a SQLHandler provides database connectivity and transaction management, reading connection details from environment variables.

app/infrastructure · high confidence

Initial database schema and domain models for users and posts

The application now includes the foundational database schema and domain models for users and posts. The database layer introduces a new SQL migration defining 'users' and 'posts' tables, along with seed data for testing. The domain layer adds Go structs for 'User' and 'Post', establishing the core data models for the application's content and authorship.

app/database, app/domain, app/log · high confidence

Initial project scaffolding with Go Clean Architecture and Docker support

The application is initialized with a Go-based Clean Architecture structure, including a main entry point that sets up logging, database connectivity, and dispatching. A .env\_example file provides default configuration for MySQL, and a .realize.yaml file configures the Go development environment. Additionally, Dockerfiles are added for the Go application and a MySQL 5.7 database container, along with a MySQL configuration file to enforce UTF-8 character sets.

app, docker · high confidence

Introduce Post and User controllers and repositories for the interface layer

The application now includes concrete implementations for handling Posts and Users at the interface layer. This adds PostController and UserController to manage HTTP requests, delegating to PostInteractor and UserInteractor respectively. It also introduces PostRepository and UserRepository to handle SQL operations for Posts and Users, along with the necessary SQLHandler interfaces to abstract database interactions.

app/interfaces · high confidence

Dependencies

Initial Go module and dependency setup

Added go.mod and go.sum files to establish the Go module for the project, defining the module path and initial dependencies including go-chi v4.0.2, go-sql-driver/mysql v1.4.1, and google.golang.org/appengine v1.6.5.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 50 → 50 (+0.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.6)
  • Architecture 69 → 69 (+0.0)
  • Maturity 61 → 61 (+0.0)
  • Readiness 23 → 25 (+1.9)
  • Security 95 → 93 (-2.7)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (14)

  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (app/infrastructure/logger.go)
  • Duplicated block (9 lines × 2) (app/interfaces/post_controller.go)
  • Duplicated block (9 lines × 3) (app/interfaces/post_controller.go)
  • Medium CVE: GO-2021-0226 (go.mod)
  • Medium CVE: GO-2026-4316 (go.mod)
  • Medium IaC: CKV_DOCKER_3 (docker/go/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (docker/mysql/Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (docker/mysql/Dockerfile)
  • No exposed public API
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient

New (15)

  • Deprecated module: github.com/go-chi/chi
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (app/infrastructure/logger.go)
  • Duplicated block (10 lines × 2) (app/interfaces/post_controller.go)
  • Duplicated block (8 lines × 5) (app/interfaces/post_controller.go)
  • High: security finding (details withheld)
  • Low IaC: DS-0026 (docker/go/Dockerfile)
  • Medium CVE: GO-2021-0226 (go.mod)
  • Medium CVE: GO-2026-4316 (go.mod)
  • Medium IaC: WD-DOCKER-0003 (docker/go/Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (docker/mysql/Dockerfile)
  • Medium: security finding (details withheld)
  • Members sharing a duplicated core (5 members, 50+ identical tokens) (app/interfaces/post_controller.go)
  • No dependency advisory monitoring
  • Outdated: github.com/go-sql-driver/mysql

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bmf-san/go-clean-architecture-web-application-boilerplate was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9417b80e7303f8409f3ae9812fee922b44621df5 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.