golangid/candi
57.0
Adequate · 21 September 2026
21.2k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based microservice framework and library that provides scaffolding, configuration, and infrastructure abstractions for building distributed applications. It standardizes the implementation of HTTP, gRPC, and GraphQL servers alongside workers for Kafka, RabbitMQ, Redis, and PostgreSQL, while managing dependencies like databases, caching, and distributed locking through a centralized container. The framework also includes utilities for environment parsing, validation, logging, and tracing, enabling developers to rapidly generate and run modular, observable microservices.
How it got here
2020 — Candi library v1.20.1 release and framework refactoring
42 changes.
The project released Candi library v1.20.1, introducing a CLI scaffolding tool and renaming the module to golangid/candi. This period focused on a comprehensive architectural overhaul, replacing legacy HTTP/gRPC servers and factory patterns with modern, configurable components using go-chi, OpenTelemetry, and centralized dependency injection. Key features included unified database configuration, new GraphQL and WebSocket support, and enhanced worker implementations for Kafka, Redis, and task queues.
2021–2022 — Worker infrastructure and test automation
15 changes.
This period focused on expanding the application's event-driven architecture by introducing dedicated workers for PostgreSQL Change Data Capture and RabbitMQ message consumption, alongside a unified broker abstraction. To support these new components, the team implemented an environment-driven application factory and significantly improved test coverage by generating extensive mocks for core interfaces, dependencies, and utilities.
Features
Add GraphQL over WebSocket support
The application now supports real-time GraphQL subscriptions via WebSocket using the \graphql-ws\ protocol. This change introduces a new HTTP handler that upgrades compatible connections to WebSocket, manages the connection lifecycle (including initialization, keep-alives, and termination), and routes subscription requests to the underlying GraphQL service. Clients can now subscribe to live data updates in addition to standard HTTP-based queries and mutations.
_codebase/app/graphql\server/ws · high confidence
Add Postgres Event Listener worker for Change Data Capture
Introduces a new Postgres Event Listener worker that monitors database tables for INSERT, UPDATE, and DELETE operations via PostgreSQL triggers and \pg\_notify\. This component automatically creates the necessary database functions and triggers, supports listening to multiple database sources, and routes events to registered handlers with configurable concurrency limits and Redis-based locking for distributed environments.
_codebase/app/postgres\worker · high confidence
CLI project generator refactored with new monorepo and modular scaffolding commands
The \candi\ CLI project generator has been restructured to support a more modular workflow and monorepo architectures. Users can now explicitly initialize services (\--init\), add modules (\--add-module\), or add delivery handlers (\--add-handler\) to existing services, with dedicated logic in \project\_generator\_add\_handler.go\ and \project\_generator\_add\_usecase.go\ to inject code into existing projects. The generator now supports monorepo initialization (\--init-monorepo\) and includes a \service\_runner\ to manage multiple services within a monorepo. New plugin support allows for extensible worker handlers (e.g., GCP PubSub, STOMP, MQTT) via \plugin.go\, and the CLI parser (\cli\_parser.go\) and constants (\constant.go\) have been separated to improve maintainability and input validation.
cmd · high confidence
Candi library v1.20.1 release with project scaffolding CLI and Apache 2.0 license
This release updates the Candi library version to v1.20.1 and introduces the \candi\ CLI tool for generating Go microservice projects and modules. The repository is now licensed under Apache 2.0, and the project structure has been refined by removing the legacy root \main.go\ and \.env.sample\ files in favor of service-specific configurations. The \Makefile\ has been updated to support mock generation and unit testing with race detection, and the project has been renamed to \golangid/candi\.
(repo-wide) · high confidence
Centralized type definitions for services, workers, and middleware
The \codebase/factory/types\ package now provides a unified set of type definitions and constants for the application's core abstractions. This includes explicit string constants for server types (REST, gRPC, GraphQL), worker types (Kafka, Redis, RabbitMQ, Scheduler, TaskQueue, PostgresListener), and database types (SQL, Mongo, Redis, ElasticSearch). Additionally, it introduces the \MiddlewareGroup\ type for registering middleware functions against specific methods or protobuf descriptors, and the \WorkerHandler\ structure with options for configuring tracing, auto-ACK, and custom configs, enabling more structured and configurable worker and middleware implementations.
codebase/factory/types · high confidence
Introduce RabbitMQ consumer worker with event-driven handler support
This change adds a new RabbitMQ consumer worker component that enables event-driven message processing. It introduces a structured handler interface (WorkerHandler) allowing developers to mount specific queue handlers, which are then registered via a dependency injection factory. The worker supports configurable options such as max goroutines, debug mode, and consumer groups, and integrates with the existing tracing system to log trace IDs and handle panics gracefully. It also includes a README example demonstrating how to create and register a RabbitMQ handler within the application's module structure.
_codebase/app/rabbitmq\worker · high confidence
Introduce centralized dependency injection container
The application now provides a centralized dependency container (\codebase/factory/dependency\) that manages core infrastructure services including SQL, MongoDB, and Redis databases (supporting both primary and named multi-instance configurations), message brokers, middleware, RSA keys, validators, and lockers. This container allows developers to configure these dependencies via functional options during initialization and access them through a unified interface or global helper functions, simplifying service wiring and lifecycle management.
codebase/factory/dependency · high confidence
Introduce cron job scheduler worker with distributed locking
Added a new cron worker component that allows scheduling jobs using cron expressions, standard durations, or custom start-time patterns. The worker includes a distributed locking mechanism (defaulting to Redis) to prevent concurrent execution across multiple instances, limits concurrent goroutines to manage load, and integrates with the existing tracer and logger for observability.
_codebase/app/cron\worker · high confidence
Introduce unified broker abstraction with Kafka, RabbitMQ, and Redis support
The broker package now provides a centralized interface for publishing and consuming messages across multiple backends. Users can register Kafka (via IBM Sarama), RabbitMQ (via amqp091-go), and Redis (using key expiration events) brokers through a unified \InitBrokers\ API. This change introduces support for delayed message consumption in RabbitMQ via the \x-delay\ header and adds trace context propagation to publisher messages, ensuring observability across distributed message flows.
broker · high confidence
Introduces configurable application lifecycle management with graceful shutdown
The application now includes a central runner that manages the startup and shutdown of registered services. Users benefit from automatic graceful shutdown handling when receiving interrupt signals (SIGINT/SIGTERM), allowing services to complete in-flight work within a configurable timeout period. The runner also supports manual shutdown triggers, custom quit signal definitions, and an optional callback function that executes after the shutdown process completes, providing better control over application termination and resource cleanup.
codebase/app · high confidence
Logger now supports custom output writers and sensitive data masking
The logger has been refactored to use the Zap library with a new initialization pattern that accepts options, allowing users to configure custom output writers (e.g., for file or test output) via \OptionAddWriter\ or \OptionSetWriter\. Additionally, a new masking capability has been added to protect sensitive information in logs; users can define custom masking rules using \SetMaskLog\ with a \Masker\ implementation, which supports pattern-based redaction for keywords like passwords, emails, and credit card numbers in JSON, query strings, and XML formats.
logger · high confidence
New GraphQL server with introspection controls and security directives
The \codebase/app/graphql\_server\ module now provides a dedicated GraphQL HTTP server that automatically constructs resolvers from registered service modules and supports custom schema sources. Users can enable an optional introspection disable flag to prevent schema exposure in production environments, addressing potential security vulnerabilities. The server includes built-in support for the GraphQL Playground and Voyager interfaces, configurable TLS listeners, and integrates with existing middleware for authentication and ACL permissions via custom directives. It also features detailed tracing and logging for query performance and error handling.
_codebase/app/graphql\server · high confidence
New Redis cache implementation with generic command execution
The cache layer now includes a new Redis-based implementation (RedisCache) that supports standard operations like Get, Set, Delete, and TTL retrieval, along with a new DoCommand method allowing execution of arbitrary Redis commands. This implementation integrates with the tracer for observability and uses separate read/write connection pools.
cache · high confidence
New factory interfaces for application, module, and service configuration
The codebase/factory package now exposes three new interfaces—AppServerFactory, ModuleFactory, and ServiceFactory—that standardize how server instances, module handlers (REST, gRPC, GraphQL, Worker, and custom Server), and service-level dependencies/configurations are accessed. This provides a consistent abstraction layer for retrieving application components and their configurations within the framework.
codebase/factory · high confidence
New interface definitions for core infrastructure and middleware
The \codebase/interfaces\ package now provides explicit Go interfaces for the system's core capabilities, including Broker, Cache, Database (SQL, Mongo, Redis), Locker, and various Handler types (REST, gRPC, GraphQL, Worker). It also introduces dedicated interfaces for Middleware (covering HTTP, gRPC, and GraphQL with specific ACL permission support), Publisher, REST routing, RSA keys, and Validation. These definitions standardize how implementations for these components are structured and consumed within the codebase.
codebase/interfaces · high confidence
New shared utilities for context, database updates, and error handling
The candishared package introduces several new capabilities: a structured context system with typed keys (HTTP headers, token claims, worker keys) and helper functions; a database update tool that converts structs to maps for partial updates across GORM, MongoDB, and SQL backends, respecting tags like gorm, bson, and sql; a multi-error type with GraphQL extension support; an event context for worker handlers; and a generic queue implementation. Additionally, the package now uses jwt/v5 for token claims, aligning with the security upgrade for [CVE redacted].
candishared · high confidence
New unified middleware library with ACL, caching, and multi-protocol auth
The middleware package has been restructured and expanded to provide a unified set of cross-cutting concerns for HTTP, gRPC, and GraphQL services. Key additions include an ACL permission middleware that enforces role-based access control across all transport types, HTTP caching with configurable max-age and no-cache support, and robust authentication handlers for Basic, Bearer (JWT), and multiple auth strategies. The library now uses a builder pattern via \NewMiddlewareWithOption\ for configuration, replacing the older constructor, and integrates tracing for observability across all middleware operations.
middleware · high confidence
New utility libraries for HTTP requests, distributed locking, and concurrency
The candiutils package introduces three new capabilities: an HTTP request client that supports configurable timeouts, retries, TLS settings, and circuit breaker integration via Hystrix; a Redis-based distributed locker with support for key prefixes, time-to-live (TTL) expiration, and blocking wait-on-lock functionality; and generic worker and sync pools for managing concurrent job execution and object reuse.
candiutils · high confidence
New utility package candihelper with environment parsing, query param handling, and time utilities
The \candihelper\ package introduces a suite of helper utilities for application configuration and data handling. It adds \MustParseEnv\ to populate structs from environment variables using struct tags, and \ParseFromQueryParam\/\ParseToQueryParam\ to map URL query parameters to and from Go structs, supporting slices and pointer types. The package also provides \TryCatch\ for panic recovery, \ParseDurationExpression\ for parsing time-based schedules, and file loading helpers. Additionally, \MultiError\ has been moved to this package (marked as deprecated in favor of \candishared\) and refactored to use value semantics.
candihelper · high confidence
Redis subscriber worker with concurrency control and distributed locking
The redis\_worker module now provides a Redis pub/sub subscriber that processes messages via goroutines limited by a per-handler semaphore (defaulting to 10 concurrent jobs) to prevent resource exhaustion. It includes distributed locking via a Redis-based locker to ensure only one worker instance processes a specific event ID, and supports a broadcast mode that disables this locking. The worker registers handlers through a standard interface, starts with a startup log indicating the number of keys, and handles graceful shutdown by waiting for in-flight jobs to complete before cancelling the context.
_codebase/app/redis\worker · high confidence
Task Queue Worker introduces SQL persistence and dashboard authentication
The Task Queue Worker now supports SQL-based persistent storage (PostgreSQL, MySQL, SQLite) as an alternative to MongoDB, automatically falling back to in-memory storage if no database is available. The built-in GraphQL dashboard is now protected by optional basic authentication and supports TLS, while job retention can be managed via configurable cron expressions to automatically clean up successful jobs.
_codebase/app/task\_queue\worker · high confidence
Removals
Removal of HTTP product handler implementation
The HTTP handler for the product module has been removed from the codebase. This change eliminates the specific REST endpoint implementation for retrieving products, effectively removing this delivery mechanism from the product service's public interface.
internal/services/warung/modules/product/delivery · high confidence
Removal of hardcoded constants and utility definitions
The file pkg/helper/const.go has been deleted, removing a collection of hardcoded constants and variables previously used across the application. This includes API version prefixes (V1, V2), timezone definitions (Asia/Jakarta), token claim keys, error definitions for token handling, ANSI color codes for console output, and byte-size conversion constants. Users relying on these specific values or the associated error types from this package will need to adjust their code to use alternative sources or definitions.
pkg/helper · high confidence
Removal of internal constant definitions for module and subscriber types
The internal package \internal/factory/constant\ has been removed, eliminating the \Module\ and \Subscriber\ type definitions and their associated constants (Kafka, Redis, RabbitMQ) that were previously used to classify classifier modules and subscribers. This change removes the internal type system for identifying specific subscriber backends and module types from this location.
internal/factory/constant · high confidence
Removal of legacy HTTP and gRPC middleware implementations
The \pkg/middleware\ package has removed its previous implementations for Basic Authentication, Bearer token validation, gRPC authentication interceptors, and HTTP request logging. Corresponding test files for these components have also been deleted. This change eliminates the specific middleware logic that previously handled HTTP basic auth, JWT bearer validation, gRPC metadata authorization, and console logging for the Echo framework, indicating a shift away from these specific in-house middleware patterns.
pkg/middleware · high confidence
Removal of legacy RSA key loading utilities
The \config/key/loader.go\ file has been removed, eliminating the previous mechanism for loading RSA private and public keys from \private.key\ and \public.pem\ files using the \jwt-go\ library. This change removes the direct dependency on that specific key-loading implementation, likely as part of a broader refactoring or migration to a different configuration or authentication strategy.
config/key · high confidence
Removal of legacy warung service implementation
The legacy warung service implementation file (warung\_service.go) has been removed from the codebase. This file previously defined the service structure, including module initialization for product and user components, and exposed the service name. Its deletion indicates that this specific service definition is no longer part of the active application logic, likely replaced by a new implementation or refactored into a different location.
internal/services/warung · high confidence
Removal of user HTTP handler and route registration
The HTTP handler for the user module, including the REST endpoint registration for retrieving user data (GET /v1/user), has been removed from the codebase. This change eliminates the server-side logic and route definition previously provided by the \RestUserHandler\ in the delivery layer.
internal/services/warung/modules/user/delivery · high confidence
Behavioural changes
Centralized environment configuration with new service toggles and CORS support
The application now uses a centralized \config/env\ module to manage runtime settings, introducing explicit environment variables to enable or disable specific services such as REST, GraphQL, gRPC, Kafka, RabbitMQ, and various workers. This change adds support for configuring CORS headers (origins, methods, headers, and credentials) via environment variables, allows disabling GraphQL introspection, and introduces a shared listener mode for HTTP/gRPC servers. It also standardizes database connection parsing, adds timeouts for configuration loading, and supports multiple tracing backends (OpenTelemetry and Jaeger) through unified environment variables.
config/env · high confidence
Environment-driven application factory for servers and workers
The application factory now constructs server and worker instances automatically based on environment variables (e.g., USE\_REST, USE\_GRAPHQL, USE\_KAFKA\_CONSUMER). This change introduces a centralized entry point, NewAppFromEnvironmentConfig, which reads configuration from env.BaseEnv() to conditionally initialize components like REST, gRPC, GraphQL, and various workers (Kafka, Cron, Redis, Postgres, RabbitMQ, Task Queue). Each component is set up via dedicated setup functions (e.g., SetupRESTServer, SetupKafkaWorker) that apply default configurations derived from environment variables, while still allowing custom options to be passed in.
codebase/factory/appfactory · high confidence
HTTP response wrappers and standard library migration
The wrapper package introduces a new \WrapHTTPResponseWriter\ that buffers HTTP responses and supports connection hijacking, alongside default handlers for service status and memory statistics. The existing \HTTPResponse\ type has been migrated from the \interface{}\ type to the Go 1.18+ \any\ alias, and its internal logic now relies on the \candihelper\ and \candishared\ subpackages for constants and error handling. A new generic \NewHTTPResponseWithMeta\ function is added to simplify response construction, and the JSON/XML output methods now use standardized content-type constants from the helper package.
wrapper · high confidence
Internal cron expression parser moved to local package
The \candiutils/cronparser\ package now contains a local implementation of the cron expression parser, migrated from the deprecated \github.com/gorhill/cronexpr\ repository. This change ensures continued maintenance and stability by keeping the parsing logic (including support for standard cron fields and built-in aliases like \@daily\) within the codebase rather than relying on an external, abandoned dependency.
candiutils/cronparser · high confidence
Migration from Jaeger/OpenTracing to OpenTelemetry
The tracer library has been rewritten to use OpenTelemetry as the underlying tracing backend, replacing the previous Jaeger/OpenTracing implementation. This change introduces a new initialization function, InitOtel, which configures the OpenTelemetry SDK and OTLP exporter, while the legacy InitJaeger and InitOpenTracing functions are now deprecated wrappers that delegate to the new implementation. The update brings enhanced configuration options via the new option.go file, including support for custom error whitelists, trace ID extractors, and detailed span attributes, ensuring that existing applications can migrate their tracing infrastructure with minimal code changes.
tracer · high confidence
New Kafka worker implementation with IBM Sarama and enhanced tracing
The Kafka worker has been rewritten to use the IBM Sarama library, replacing the previous implementation. This change introduces structured tracing for every consumed message, including automatic propagation of trace IDs, logging of message headers (offset, partition, timestamp), and panic recovery that tags traces appropriately. Message processing now utilizes a pooled EventContext to reduce allocation overhead, and the worker supports configurable consumer groups, debug modes, and max goroutine limits. The worker also integrates with the existing module system via WorkerHandler interfaces, allowing handlers to be mounted by topic pattern.
_codebase/app/kafka\worker · high confidence
New gRPC server implementation with TLS, shared listener, and keepalive support
The gRPC server component has been rewritten to support TLS encryption via a configurable TLS configuration, integration with a shared multiplexed listener (cmux) for co-hosting HTTP/2 and gRPC traffic, and configurable gRPC keepalive policies to manage connection idle times and pings. It also introduces a unified interceptor chain that applies tracing and middleware to both unary and streaming RPCs, allowing for consistent logging, metadata propagation, and panic recovery across all gRPC endpoints.
_codebase/app/grpc\server · high confidence
REST server switches to go-chi and adds configurable TLS, CORS, and tracing
The REST server implementation has been rewritten to use the go-chi/v5 router instead of the previous framework, introducing a new option-based configuration model (option.go) for setting HTTP ports, root paths, custom root middlewares, and TLS certificates. The new middleware layer (middleware.go) provides built-in CORS handling that reads configuration from environment variables, automatic distributed tracing with trace ID propagation and request/response body logging, and panic recovery. The server now supports shared listeners for multiplexing and includes a memstats endpoint protected by HTTP basic auth, while maintaining backward compatibility through a route wrapper that transforms colon-based URL parameters to go-chi's brace syntax.
_codebase/app/rest\server · high confidence
Refactored application configuration and dependency loading
The configuration system has been rewritten to use the \golangid/candi\ library for environment loading and dependency management. The previous manual \.env\ parsing and direct database/Redis initialization have been replaced by a structured \Config\ object that accepts service-specific options (such as log size) and loads dependencies via a configurable function with a timeout. The application now supports a shared multiplexed listener (\cmux\) for handling HTTP and gRPC traffic on the same port, and includes improved panic recovery and graceful shutdown logic for loaded dependencies.
config · high confidence
Refactored validator to use custom JSON schema and struct validation
The validator package has been refactored to replace the external go-playground/validator dependency with a custom, internal struct validator implementation and a new JSON schema validation engine. Users can now validate documents against JSON schemas stored in memory, on the file system, or in a database, with support for custom schema storage and error filtering. The struct validation logic is now provided via a separate interface, allowing projects to implement their own validation rules without relying on the removed external library.
validator · high confidence
Regenerated interface mocks with updated signatures and types
The mock implementations in \mocks/codebase/interfaces\ have been regenerated to align with updated interface definitions. Key changes include the Cache mock adding a \GetTTL\ method, the Locker mock adding \IsLockedTTL\ and \GetTTLLocker\ methods, and the MongoDatabase mock now returning the v2 driver's \\*mongo.Database\ type. Additionally, the REST router mock now supports the \go-chi\ routing engine with methods for all HTTP verbs and middleware chaining, and the Tracer mock has been updated to use Go 1.18's \any\ type for generic arguments.
mocks/codebase/interfaces · high confidence
Removal of base module parameter struct
The \ModuleParam\ struct, which previously bundled configuration and middleware dependencies for the base factory module, has been removed from the codebase. This change eliminates the shared parameter object that was used to pass these dependencies into factory components.
internal/factory/base · high confidence
Removal of delivery interface definitions
The interface definitions for HTTP (Echo), gRPC, and message subscriber deliveries have been removed from the codebase. This eliminates the explicit contracts for mounting HTTP groups, registering gRPC servers, and processing messages, indicating a shift in how these delivery mechanisms are implemented or integrated.
internal/factory/interfaces · high confidence
Removal of generic service factory initialization
The generic service initialization logic in \internal/services/service.go\ has been removed. This file previously provided a factory function (\InitService\) that mapped service names to specific implementations (such as \warung\), allowing for dynamic service creation based on configuration. Its deletion indicates a shift away from this centralized, switch-based service registration pattern.
internal/services · medium confidence
Removal of legacy HTTP and gRPC server serving logic
The \internal/app\ package has removed the code responsible for initializing and serving HTTP (via Echo) and gRPC servers. Specifically, the \App\ struct's server fields, the \ServeHTTP\ and \ServeGRPC\ methods, and the associated \app\_http.go\ and \app\_grpc.go\ files have been deleted. This change eliminates the direct responsibility of this module for starting network listeners and mounting REST/gRPC handlers, indicating a shift in how the application's entry point and server lifecycle are managed.
internal/app · high confidence
Removal of legacy module wrapper files for product and user services
The \product\_module.go\ and \user\_module.go\ files, which previously served as module wrappers initializing REST handlers and managing version routing (V1/V2) for the product and user services, have been deleted. This change removes the specific module-layer initialization logic for these two services, likely as part of a broader refactoring to simplify the service factory or move module definitions elsewhere.
internal/services/warung/modules/product, internal/services/warung/modules/user · medium confidence
Removal of legacy service and module factory interfaces
The \ServiceFactory\ and \ModuleFactory\ interfaces have been removed from the \internal/factory\ package. This eliminates the previous abstraction layer that defined how service modules were discovered and how their REST, gRPC, and subscriber handlers were instantiated, reflecting a shift in how the application structure and handler wiring are managed.
internal/factory · high confidence
Removal of shared pagination filter struct
The shared Filter struct, which previously provided standard pagination fields (limit, page, offset, search, order by, sort) and a CalculateOffset helper, has been removed from the codebase. This eliminates the centralized pagination logic that was previously available to other packages via the shared module.
pkg/shared · high confidence
Unified database configuration with health checks and connection pooling
The database configuration layer has been refactored to provide a consistent, object-oriented interface for MongoDB, Redis, and SQL databases. Each database type now returns a dedicated instance struct (e.g., MongoInstance, RedisInstance, SQLInstance) that encapsulates read/write connections, provides explicit Health() methods for status reporting, and handles graceful disconnection. Configuration has shifted from scattered environment variables to centralized DSN-based loading via the env package, supporting single-connection fallback when read hosts are empty. Redis now includes configurable connection pool options (max idle, max active, timeouts) and integrates with a cache wrapper. MongoDB has been upgraded to driver v2, and SQL connections now support a unified DSN format with automatic driver detection for MySQL, SQLite, PostgreSQL, and SQL Server.
config/database · high confidence
Updated tracer mocks to align with golangid/candi interface changes
The mock implementations in the \mocks/tracer\ directory have been regenerated to match the updated \github.com/golangid/candi/tracer\ interface. This update includes new mock types for \FinishOptionFunc\ and \OptionFunc\, and refreshes the \PlatformType\ and \Tracer\ mocks to reflect current method signatures, such as the \Context\ method on \Tracer\ and the \Disconnect\, \GetTraceID\, and \GetTraceURL\ methods on \PlatformType\. These changes ensure that tests using these mocks remain compatible with the underlying tracer library's API.
mocks/tracer · high confidence
Test coverage
Added autogenerated mocks for broker option functions; Added autogenerated mocks for codebase interfaces; Added mock for Schedule interface; Added mock for middleware OptionFunc; Added mock implementation for the Dependency interface; Added mock implementations for middleware and worker handler types; Added mocks for FilterStreamer, MultiError, and URLQueryGetter interfaces; Updated validator mock implementations.
Dependencies
Major dependency upgrade and module rename
The project module has been renamed from github.com/agungdwiprasetyo/backend-microservices to github.com/golangid/candi, and the Go version requirement has been updated to 1.26.0. This change replaces older libraries with modern equivalents, including switching from the deprecated dgrijalva/jwt-go to golang-jwt/jwt/v5, from labstack/echo to go-chi/chi/v5, and from the original MongoDB driver to go.mongodb.org/mongo-driver/v2. It also introduces new dependencies for OpenTelemetry tracing, IBM Sarama for Kafka, and RabbitMQ, while removing legacy packages like opentracing and hystrix.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 51 → 57 (+6.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 78 → 85 (+6.1)
- Architecture 97 → 97 (-0.2)
- Maturity 49 → 50 (+0.5)
- Readiness 53 → 54 (+1.1)
- Security 42 → 59 (+17.2)
Resolved (69)
- Change coupling: acl_permission.go ↔ bearer.go (middleware/acl_permission.go)
- Change coupling: graphql_schema.go ↔ task_queue_worker.go (codebase/app/task_queue_worker/graphql_schema.go)
- Change coupling: project_generator.go ↔ init.go (cmd/candi/project_generator.go)
- Change coupling: project_generator_add_handler.go ↔ init.go (cmd/candi/project_generator_add_handler.go)
- Change coupling: subscribers.go ↔ types.go (codebase/app/task_queue_worker/subscribers.go)
- Change coupling: template_domain.go ↔ init.go (cmd/candi/template_domain.go)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (codebase/app/task_queue_worker/persistent_sql.go)
- Duplicated block (11 lines × 2) (codebase/app/task_queue_worker/persistent_mongo.go)
- Duplicated block (11 lines × 2) (codebase/app/task_queue_worker/persistent_sql.go)
- Duplicated block (12 lines × 3) (codebase/app/task_queue_worker/persistent_mongo.go)
- Duplicated block (14 lines × 2) (validator/json_schema_storage.go)
- Duplicated block (5 lines × 2) (candiutils/cronparser/parser.go)
- Duplicated block (5 lines × 2) (codebase/app/kafka_worker/kafka_worker.go)
- Duplicated block (5 lines × 2) (codebase/app/task_queue_worker/persistent_sql.go)
- Duplicated block (6 lines × 2) (codebase/app/task_queue_worker/graphql_resolver.go)
- Duplicated block (7 lines × 3) (codebase/app/cron_worker/cron_worker.go)
- Duplicated block (8 lines × 2) (cmd/candi/project_generator_add_usecase.go)
- …and 49 more
New (98)
- Change coupling: graphql_resolver.go ↔ init.go (codebase/app/task_queue_worker/graphql_resolver.go)
- Change coupling: persistent_mongo.go ↔ init.go (codebase/app/task_queue_worker/persistent_mongo.go)
- ClassTooLong: rootResolver (codebase/app/task_queue_worker/graphql_resolver.go)
- Documentation: no architecture or design documentation (README.md)
- Documentation: no project overview (README.md)
- Duplicated block (10 lines × 2) (cmd/candi/project_generator.go)
- Duplicated block (12 lines × 2) (codebase/app/task_queue_worker/persistent_mongo.go)
- Duplicated block (12–13 lines × 3) (validator/json_schema_storage.go)
- Duplicated block (13 lines × 3) (codebase/app/task_queue_worker/persistent_mongo.go)
- Duplicated block (13–14 lines × 2) (codebase/app/task_queue_worker/persistent_sql.go)
- Duplicated block (18 lines × 2) (codebase/app/task_queue_worker/persistent_sql.go)
- Duplicated block (23 lines × 2) (validator/json_schema_storage.go)
- Duplicated block (38 lines × 2) (codebase/app/kafka_worker/option.go)
- Duplicated block (5 lines × 2) (codebase/app/kafka_worker/kafka_worker.go)
- Duplicated block (5 lines × 2) (codebase/app/task_queue_worker/persistent_sql.go)
- Duplicated block (6 lines × 2) (candihelper/multierror.go)
- Duplicated block (6 lines × 2) (codebase/app/graphql_server/tracer.go)
- Duplicated block (7 lines × 2) (broker/redis.go)
- Duplicated block (7 lines × 2) (candihelper/multierror.go)
- Duplicated block (7 lines × 2) (cmd/candi/project_generator_add_usecase.go)
- …and 78 more
Changes since last survey
- 2 commits — 2 feature/other, 0 fixes
By area
- (root) — 2 commits
Notable commits
- change: add marshal json method in multierror
- change: upgrade go.mod
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
golangid/candi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0521dadf4dee1e509cd060b755d19626d9a503a0 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.