damasamirulkarim/go-hexagonal-architecture
70.0
Adequate · 21 September 2026
58
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a command-line application with an internal package structure, characterized by a single behavioral change across its core components. It appears to be a relatively small or early-stage codebase where the primary activity has been modifying existing behavior rather than adding new features.
Behavioural changes
1 commit (0 fixes) modifying cmd, internal, pkg
A change to existing behaviour in cmd, internal, pkg — 1 commit, 19 files.
cmd, internal, pkg · low confidence · unverified
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 70 → 70 (+0.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 65 → 65 (+0.0)
- Readiness 72 → 68 (-4.3)
- Security 78 → 92 (+13.8)
Resolved (16)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2024-2824 (go.mod)
- No exposed public API
- Test reliability not included
- The README does not mention where to get or run the application code (e.g. how to build/run the server/cmd), which is standard missing from such docs when only one file exists. (README.md)
- early-stage repository — too little history to judge knowledge freshness
- git history depth insufficient
- single-commit history — no usable git history window to measure hotspots
- single-maintainer — knowledge-concentration (bus factor) risk
New (17)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2024-2824 (go.mod)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No ADRs found
- No dependency advisory monitoring
- Workflow token permissions not restricted
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
damasamirulkarim/go-hexagonal-architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b6206b75e8ec3564fccd3dbd23b100d6f56d59ee — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.