Skip to content
CAI
Software that uses CAICheck a score

dipeshdulal/clean-gin

42.3

Weak · 21 September 2026

1.1k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based web application built on a clean architecture, utilizing the Gin framework for HTTP routing and Go-FX for dependency injection. It provides a RESTful API for user management and JWT-based authentication, supported by a service and repository layer that interact with a MySQL database via GORM. The application also includes a CLI interface for server execution and background tasks, with infrastructure managed through Docker and automated database migrations.

Features

Add User model for database mapping

The application now includes a User model that maps to the 'users' database table, defining fields for ID, name, email, age, birthday, member number, and timestamps. This enables database interactions for user data.

models · high confidence

Added CLI interface for running the application

The application now includes a command-line interface built with Cobra, allowing users to start the server via the 'app:serve' command. This CLI leverages the same dependency injection container and services used by the main application, enabling script execution and background tasks using the existing infrastructure.

bootstrap, commands · high confidence

Added CORS, JWT authentication, and database transaction middleware

The application now includes three new middleware components: CORS headers for handling cross-origin requests, JWT-based authentication for securing endpoints, and a database transaction handler that automatically commits or rolls back database operations based on the HTTP response status. These are registered via dependency injection and applied globally to the Gin router.

api/middlewares · high confidence

Initial project setup with clean architecture, Docker, and migration tooling

The project is initialized with a clean architecture template using the Gin framework, Go-FX for dependency injection, and GORM for database operations. A Makefile is added to manage database migrations via sql-migrate, supporting both Docker and host environments. Docker Compose configurations are introduced to run the web server, MySQL database, and Adminer, with environment variables loaded from a new .env.example file. The project also includes a logo, a BSD 0-Clause license, and updated documentation in README.md.

(repo-wide) · high confidence

Introduce service layer for user management and JWT authentication

Added a new service layer that implements user CRUD operations and JWT-based authentication. The \services\ package now includes \UserService\ for creating, reading, updating, and deleting users, as well as \JWTAuthService\ for generating and validating JSON Web Tokens. These services are registered in the application's dependency injection container via \fx.Provide\.

services · high confidence

Introduce shared lib package with centralized configuration, logging, and database setup

Users can now benefit from a unified \lib\ package that centralizes environment variable loading via Viper, structured logging through Zap (with configurable log levels and output), and database connection setup using GORM. This includes a new \Env\ struct for configuration, a \Logger\ wrapper for consistent logging across Gin, FX, and GORM, and a \Database\ helper for establishing MySQL connections. The package also provides a \Command\ interface for Cobra-based CLI subcommands and registers all these components via an FX module for dependency injection.

lib · high confidence

Introduce user repository with dependency injection

Users can now be managed through a new user repository that supports database transactions. The repository is implemented in Go using GORM and integrates with the application's logging system. The module is wired into the application's dependency injection container via fx, providing a structured way to access user data operations.

repository · high confidence

Introduced new controllers and route handlers for user and authentication endpoints

The API now exposes user and authentication endpoints through newly created controllers and route handlers. Users can now access user management endpoints (GET/POST/DELETE /api/user) protected by JWT authentication, as well as authentication routes (POST /auth/login, /auth/register). The controllers handle request binding, error handling, and service layer invocation, while the route setup organizes these endpoints under their respective paths.

api/controllers · high confidence

Behavioural changes

Add database transaction context key

A new constant, DBTransaction, is introduced in the constants package to define the context key used for the database transaction handle within the router context.

constants · medium confidence

Added initial users table migration

A new database migration file has been added to define the 'users' table schema, including fields for email, name, age, birthday, and member number, along with corresponding up and down migration steps.

migration · medium confidence

Docker environment updated to use sql-migrate and Delve for debugging

The Docker setup now installs the sql-migrate and Delve (dlv) tools during the build process, replacing the previous compile daemon approach. The web image includes inotify-tools and Go dependencies, and the run script uses Delve for headless debugging with inotify-based hot-reloading. The MySQL image is configured with utf8mb4 character set support.

docker · medium confidence

Introduced domain interfaces for authentication and user services

Added new domain interfaces for authentication and user services. The auth service now exposes an interface for authorizing tokens and creating tokens, while the user service interface defines methods for user retrieval, creation, update, and deletion, supporting transactional operations.

domains · high confidence

Removal of empty placeholder directories

The empty placeholder files (.gitkeep) in the controllers, init, and routers directories have been removed. This cleanup eliminates empty directories that were previously used as structural placeholders, indicating that the codebase has been refactored to remove unnecessary scaffolding.

controllers, init, routers · high confidence

Dependencies

Updated Go dependencies and upgraded to Go 1.17

The project's go.mod file has been updated to require Go version 1.17. A significant number of dependencies have been added or upgraded, including the Gin web framework (v1.7.7), the MySQL driver (v1.6.0), Viper (v1.10.1) for configuration management, Cobra (v1.4.0) for CLI setup, Zap (v1.21.0) for logging, and GORM with its MySQL driver for database operations. Additional indirect dependencies for validation, environment variable loading, and other utilities have also been introduced.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 41 → 42 (+1.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (-0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 53 → 53 (+0.0)
  • Readiness 12 → 15 (+3.5)
  • Security 88 → 89 (+1.0)

Resolved (13)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High IaC: DS-0025 (docker/web.Dockerfile)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2022-0969 (go.mod)
  • Medium IaC: CKV_DOCKER_3 (docker/db.Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (docker/web.Dockerfile)
  • No exposed public API
  • dormant codebase — no living knowledge left to concentrate

New (30)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/rs/cors/wrapper/gin
  • Duplicated block (9 lines × 2) (lib/logger.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High IaC: DS-0025 (docker/web.Dockerfile)
  • High IaC: DS-0025 (docker/web.Dockerfile)
  • High IaC: DS-0025 (docker/web.Dockerfile)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Low IaC: DS-0026 (docker/db.Dockerfile)
  • Low IaC: DS-0026 (docker/web.Dockerfile)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2022-0969 (go.mod)
  • Medium IaC: WD-DOCKER-0003 (docker/db.Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (docker/web.Dockerfile)
  • Medium IaC: WD-DOCKER-0004 (docker/web.Dockerfile)
  • Medium IaC: WD-DOCKER-0004 (docker/web.Dockerfile)
  • Medium IaC: WD-DOCKER-0010 (docker/web.Dockerfile)
  • …and 10 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

dipeshdulal/clean-gin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1011175b3b77a88be15a64d3593a80819baa6221 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.