Skip to content
CAI
Software that uses CAICheck a score

Caknoooo/go-gin-clean-starter

50.0

Adequate · 20 September 2026

2.3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based web application scaffolded with Clean Architecture, providing a foundational structure for building RESTful APIs. It implements core user management and authentication features, including registration, login, email verification, and JWT-based session handling. The platform supports database operations through GORM with PostgreSQL, featuring automated migrations, seeding, and structured entity management.

How it got here

2023 — Initial project scaffolding

3 changes.

This period established the foundational structure of the Go Gin Clean Starter application, implementing a Clean Architecture layout with controller, service, and repository layers. It introduced essential infrastructure including Docker support, database configuration via GORM, and core dependency management using Go modules.

2024–2025 — Core architecture and feature implementation

9 changes.

This period focused on establishing the application's foundational architecture by restructuring the entry point with dependency injection and implementing a Go-based database migration system. It introduced core modules for user management and authentication, supported by new middleware, utility packages, and Docker configuration for development and deployment.

Features

Add Docker configuration for Go app with Air hot reload and Nginx proxy

The project now includes Docker support for local development and deployment. A new Dockerfile sets up a Go 1.26 Alpine environment, installs the 'air' tool (v1.65.1) for hot reloading, and runs the application via 'air'. An Nginx configuration file is added to proxy traffic from port 80 to the application on port 8888, handling WebSocket upgrades and caching bypass. Additionally, .gitignore files are created for the 'air' and 'postgresql' directories to manage version control artifacts.

docker · high confidence

Added authentication and CORS middleware implementations

The middlewares package now includes dedicated handlers for cross-origin resource sharing and request authentication. The new CORS middleware enables cross-origin requests with broad method and header allowances, while the authentication middleware validates Bearer tokens using a JWT service, extracting user IDs and rejecting unauthorized or invalid requests with specific error responses.

middlewares · high confidence

Added core utility packages for authentication, encryption, and email

This change introduces several new utility packages to support application functionality. It adds password hashing and verification helpers using bcrypt, and AES-GCM encryption/decryption utilities for data protection. It also includes an email service for sending HTML templates (specifically for account verification) and standard JSON response builders for API consistency. Additionally, constants for roles and pagination are defined, and a file upload utility is provided to handle multipart file storage.

pkg · high confidence

Initial database, email, and logging configuration setup

The application now includes initial configuration files for database connectivity, email settings, and query logging. Database connections are established using GORM with support for PostgreSQL (via environment variables) and SQLite (for testing/in-memory use), including automatic creation of the uuid-ossp extension. Email configuration is loaded via Viper from the .env file, and a custom GORM logger is set up to write slow query logs to monthly files in the config/logs directory.

config · high confidence

Initial project scaffolding with clean architecture, Docker, and migration tools

This release establishes the foundational structure for the Go Gin Clean Starter application. It introduces a Clean Architecture layout (Controller-Service-Repository) with a shell script to auto-generate new modules. The project now includes a comprehensive Makefile for managing dependencies, running the application, and executing database migrations and seeders (both locally and via Docker). Docker support is added via docker-compose.yml and an .air.toml configuration for hot-reloading during development. Additionally, an .env.example file provides configuration templates for PostgreSQL, SMTP, and JWT, and a static HTML page is included for viewing query logs.

(repo-wide) · high confidence

Initial user management module with validation and pagination

This change introduces the complete user management module, providing endpoints to retrieve user lists with pagination, fetch the current user profile, and update or delete user accounts. It includes a new validation layer using go-playground/validator for user creation and update requests, ensuring data integrity for fields like phone numbers and names. The implementation follows a clean architecture pattern with distinct controller, service, repository, and DTO layers, and integrates with the existing dependency injection container for route registration.

modules/user · high confidence

New CLI commands for database migrations and custom script execution

A new \script\ package introduces a command-line interface for managing database migrations and running custom scripts. Users can now execute migrations (\--migrate\), rollback specific batches or all migrations (\--migrate:rollback\, \--migrate:rollback:all\), check status (\--migrate:status\), create new migration files (\--migrate:create:\<name\>\), and run database seeders (\--seed\). Additionally, the system supports running custom scripts via the \--script:\<name\>\ flag, with an example script provided to demonstrate the pattern.

script · high confidence

New authentication module with registration, login, and token management

This change introduces the complete authentication module for the application. Users can now register accounts, log in, and manage sessions via access and refresh tokens. The system includes email verification workflows (sending and verifying emails) and password reset capabilities. It relies on a new JWT service for token generation and validation, a refresh token repository for persistent session storage, and structured validation for all API requests.

modules/auth · high confidence

Behavioural changes

Application entry point restructured with new dependency injection and module registration

The application's entry point has been reorganized to use the 'do' dependency injection framework for registering dependencies via 'providers.RegisterDependencies'. The main function now explicitly initializes the Gin engine, applies CORS middleware, and registers routes for the 'user' and 'auth' modules. Additionally, the server startup logic now supports configuration via the 'GOLANG\_PORT' environment variable (defaulting to 8888) and distinguishes binding addresses based on the 'APP\_ENV' setting, while also displaying a startup banner.

cmd · high confidence

Centralized dependency injection for authentication and user modules

The providers package now includes a new core.go file that consolidates the initialization of the database connection and the registration of dependencies for the auth and user modules. This change introduces a structured approach to wiring services, repositories, and controllers using the do dependency injection library, ensuring that components like JWT service, user repository, and auth service are properly instantiated and injected into their respective controllers.

providers · high confidence

Database layer restructured with Go-based migration and seeding system

The database package has been reorganized to use Go-based entity definitions and a custom migration manager instead of raw SQL files. This introduces structured entity models for Users, RefreshTokens, and Migrations, along with a new migration system that tracks execution batches and supports rollbacks. A new seeder system has been added to populate initial data, including default admin and user accounts from JSON seed files.

database · high confidence

Dependencies

Initial Go module setup with Go 1.26 and core dependencies

The project initializes its Go module (\go.mod\) targeting Go 1.26.0, establishing the foundational dependency graph for the application. This includes the Gin web framework (v1.12.0), GORM with PostgreSQL and SQLite drivers, JWT authentication, and validation libraries, alongside a custom pagination package and dependency injection container.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 49 → 50 (+0.7)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 91 → 94 (+3.2)
  • Architecture 100 → 92 (-8.0)
  • Maturity 80 → 66 (-14.2)
  • Readiness 31 → 35 (+3.6)
  • Security 70 → 70 (+0.4)
  • Domain Modelling 72 → 76 (+4.3)
  • Accessibility 52 → 52 (+0.0)

Resolved (24)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (12 lines × 2) (modules/user/repository/user_repository.go)
  • Duplicated block (16 lines × 2) (database/manager.go)
  • Further orphaned files (smaller)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 4 more

New (32)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/common-nighthawk/go-figure
  • Dependency pinned to a stale untagged commit: gopkg.in/gomail.v2
  • Duplicated block (11 lines × 2) (modules/auth/repository/refresh_token_repository.go)
  • Duplicated block (11 lines × 2) (modules/user/repository/user_repository.go)
  • Duplicated block (34 lines × 2) (database/manager.go)
  • Duplicated block (9 lines × 2) (modules/auth/controller/auth_controller.go)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2026-4599 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: WD-DOCKER-0003 (docker/Dockerfile)
  • Medium IaC: WD-DOCKER-0010 (docker/Dockerfile)
  • …and 12 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Caknoooo/go-gin-clean-starter was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bd68156a6bfc2be8bd8b7633ccab43bfde52232b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.