Skip to content
CAI
Software that uses CAICheck a score

DoWithLogic/golang-clean-architecture

48.5

Weak · 21 September 2026

3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Go-based backend service implementing Clean Architecture, designed to manage user accounts and authentication. It provides HTTP endpoints for user registration, login, and profile management, backed by MySQL and Redis. The system includes comprehensive observability features such as structured logging, metrics, and distributed tracing, along with robust testing coverage for both unit and integration scenarios.

How it got here

2023 — Initial project scaffolding and architecture setup

8 changes.

This period marks the initial release of a Go application built on Clean Architecture and SOLID principles. The work involved establishing the foundational project structure, including Dockerfiles, Makefiles, and core packages for logging, encryption, and database connectivity. It also included the removal of legacy initialization code and the introduction of new configuration schemas and database migrations.

2024–2026 — User management and server refactoring

5 changes.

This period focused on implementing core user management features, including authentication and profile handling via new API endpoints. The work also involved refactoring the server initialization to improve separation of concerns and adding comprehensive test coverage with mocks and integration tests.

Features

Add structured HTTP logging middleware and refactor Echo server setup

The \pkg/logging\ package now provides a reusable Echo middleware that logs structured HTTP request and response data using zerolog. It supports sensitive-field masking (redacting keys like 'password' or 'token'), path exclusion (skipping health-check or metrics endpoints), and X-Request-ID propagation. The \pkg/app\_echo\ package was refactored to integrate this new logging middleware, add cache-revalidation headers, and configure CORS, Prometheus, and OpenTelemetry observability. Additionally, the \pkg/datasources\ package now offers functional options for configuring MySQL and PostgreSQL connections, including connection pool sizes, metrics, and tracing. The \pkg/encryptions\ package introduces AES-256-GCM encryption and various cryptographic utilities (HMAC, Base64, MD5, SHA). The \pkg/jwt\ package implements JWT token creation, verification, and Redis-based blacklisting. All new functionality is accompanied by comprehensive unit and integration tests.

pkg · high confidence

Add user table migration for database schema

A new database migration has been added to create the 'users' table, which includes fields for name, contact information (email or phone), birth date, language preference, and password. The table also tracks status (pending, active, reject, closed) and includes timestamps for creation, updates, and soft deletes.

database · high confidence

Initial release of the Go clean architecture application

The repository is initialized with a Go application implementing Clean Architecture and SOLID principles. This includes the main entry point (main.go) that configures observability (tracing and metrics), a Dockerfile for containerized builds, a Makefile with targets for environment setup, database migrations, and running unit/integration tests, along with standard project files like README.md, LICENSE.md, and .gitignore.

(repo-wide) · high confidence

User management endpoints and logic

Added HTTP handlers, routes, DTOs, entities, repository, and use-case implementations for user management. Users can now sign up, log in, and retrieve or update their profile details via new public and private API endpoints. The update user endpoint now enforces a database transaction to ensure data consistency during profile modifications.

internal/app/users · high confidence

Removals

Removal of legacy app and infrastructure initialization code

The legacy app initialization and infrastructure setup code has been removed. Specifically, the App struct and its NewApp constructor, the StartService method that wired up repositories, use cases, and routes, and the infrastructure helpers for database and Echo server creation have all been deleted from internal/app and internal/infrastructure. This eliminates the old initialization flow, meaning the application now relies on a different, likely more modular, startup process.

internal/app · high confidence

Removed legacy user management implementation

The internal/users module's HTTP handlers, routes, DTOs, entities, repository layer, and use cases have been deleted. This removes the existing user creation and update endpoints and their associated data models and database queries.

internal/users · high confidence

Removed main.go entry point from cmd directory

The main.go file, which previously served as the application entry point for loading configuration and starting the app, has been removed from the cmd directory. This change eliminates the previous method of initializing and starting the application from this specific file.

cmd · high confidence

Behavioural changes

Added .coverage directory placeholder

A new .coverage directory has been added to the repository, containing a .keep file to ensure the directory is tracked by version control.

.coverage · high confidence

Refactored server initialization and route registration

The server startup logic has been reorganized to improve separation of concerns. The \NewServer\ constructor now handles the creation of database, Redis, and Echo HTTP server instances, while a new \setup\ method in \handlers.go\ is responsible for configuring middleware and registering API routes. This change decouples the HTTP server setup from the application's core logic, making the codebase easier to maintain and extend.

internal/server · high confidence

Restructured and expanded configuration schema with new service integrations

The application's configuration has been restructured from a flat, environment-based loading mechanism to a more modular structure supporting App, Server, Database, Authentication, Observability, JWT, and Redis settings. This change introduces dedicated configuration structs for each domain, replacing the previous generic ServerConfig and DatabaseConfig. The system now supports loading configuration via both environment name and explicit file path, and includes new settings for JWT authentication keys and Redis connectivity, reflecting the addition of these services to the architecture.

config · medium confidence

Test coverage

Added MySQL integration test suite; Added user domain mocks for testing.

Dependencies

Updated Go dependencies and upgraded to Go 1.25.0

The project's go.mod has been updated to require Go 1.25.0. The dependency list was significantly expanded and modernized: the MySQL driver was upgraded from v1.6.0 to v1.9.3, and the Echo framework was updated from v4.11.1 to v4.12.0. New dependencies were added for Redis (go-redis, miniredis), JWT authentication (golang-jwt), OpenTelemetry tracing, testcontainers for integration testing, and various utility libraries (e.g., go-faker, testcontainers). Many older indirect dependencies were replaced with newer versions or removed, reflecting a comprehensive update to the project's build configuration.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 46 → 48 (+2.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.3)
  • Architecture 100 → 91 (-8.6)
  • Maturity 66 → 67 (+0.4)
  • Readiness 32 → 37 (+5.3)
  • Security 78 → 78 (-0.5)
  • Domain Modelling 38 → 38 (+0.0)

Resolved (21)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (14 lines × 2) (pkg/datasources/mysql.go)
  • Duplicated block (9 lines × 2) (internal/app/users/delivery/http/v1/handlers.go)
  • Duplicated block (9 lines × 2) (pkg/response/generic_handler.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2025-3955 (go.mod)
  • Medium CVE: GO-2026-5158 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • Medium IaC: CKV_DOCKER_7 (Dockerfile)
  • Medium vulnerability: GO-2026-5841 (go.mod)
  • No exposed public API
  • Small-team knowledge concentration
  • …and 1 more

New (64)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Deprecated module: go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (internal/app/users/delivery/http/v1/handlers.go)
  • Duplicated block (24 lines × 2) (pkg/datasources/mysql.go)
  • Duplicated block (7 lines × 2) (pkg/response/generic_handler.go)
  • Duplicated block (8 lines × 2) (pkg/testutil/mysql.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High IaC: WD-COMPOSE-0002 (infrastructure/docker-compose.local.yml)
  • Low CVE: [GHSA redacted] (go.mod)
  • Low CVE: [GHSA redacted] (go.mod)
  • Low cohesion: Crypto (LCOM4 7) (pkg/encryptions/crypto.go)
  • Medium CVE: [GHSA redacted] (go.mod)
  • …and 44 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

DoWithLogic/golang-clean-architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c918cf10fed2c580906216e653d473cff1214da3 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.