Skip to content
CAI
Software that uses CAICheck a score

jeroenrinzema/commander

63.3

Adequate · 21 September 2026

3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add Kafka example demonstrating sync and async command handling

A new Kafka dialect example has been added to the codebase, providing a complete, runnable application that demonstrates how to use the Commander library with Apache Kafka. The example includes a README with setup instructions and a main.go file that configures a Kafka connection, defines command and event topics, and exposes HTTP endpoints for both synchronous and asynchronous command execution.

examples/kafka · high confidence

Add Zipkin tracing example for Commander

A new example application demonstrating how to integrate Zipkin distributed tracing with the Commander framework. The example uses the in-memory Mock dialect and configures HTTP handlers to capture and propagate trace spans, exposing trace headers in HTTP responses to facilitate observability.

examples/zipkin · high confidence

Add in-memory mock dialect for unit testing

A new mock dialect implementation has been added to the \dialects/mock\ package, providing an in-memory message broker for use in unit tests. This includes the core \Dialect\, \Consumer\, and \Producer\ structs, along with subscription management and thread-safe message routing. The addition is accompanied by corresponding test files (\consumer\_test.go\, \main\_test.go\, \producer\_test.go\) that verify message publishing, consumption, and dialect lifecycle operations.

dialects/mock · high confidence

Add initial Kafka dialect for message consumption and production

Users can now connect to an Apache Kafka cluster using a connection string containing broker addresses, group ID, Kafka version, and initial offset. The new \kafka\ dialect provides \Consumer()\ and \Producer()\ interfaces to interact with Kafka, supporting configuration via key-value pairs in the connection string (e.g., \brokers=...\, \group=...\, \version=...\).

dialects/kafka · high confidence

Add mock dialect example for in-memory pub/sub

A new example application is provided in the \examples/mock\ directory, demonstrating the use of the in-memory Mock dialect for pub/sub operations without third-party dependencies. The example includes a \main.go\ file that sets up a Commander client with JSON codec and await timeout, handling an HTTP request to execute a sync command and return the resulting event, alongside a README explaining the setup.

examples/mock · high confidence

Add mock multiple groups example

Introduces a new example application demonstrating the use of multiple groups with the mock dialect. The example simulates executing multiple groups and awaiting multiple events, specifically handling a sync \purchase\ command that triggers an \available\ event. It includes a HTTP server on port 8080 to simulate the purchase command and process the response.

examples/mock-multiple-groups · high confidence

Added Kafka consumer and producer dialects

Introduced new Kafka dialects for both consuming and producing messages. The consumer implementation supports both partition-based and group-based consumption, allowing users to subscribe to topics and receive messages via channels. The producer implementation enables sending messages to Kafka topics. These additions provide the foundational infrastructure for Kafka integration within the Commander framework.

dialects/kafka/consumer · high confidence

Added Kafka metadata extraction and serialization for message headers

The Kafka dialect now includes dedicated files (header.go, main.go, message.go) that define how Kafka message headers are mapped to and from the internal Commander message model. This adds support for extracting metadata such as ID, action, status code, version, parent ID, and parent timestamp from Kafka headers, as well as serializing these fields back into Kafka headers for production.

dialects/kafka/metadata · high confidence

Added circuit breaker and readiness gate components

Introduced a new \circuit\ package containing a \Breaker\ struct that manages a concurrent-safe open/closed state, and a \Ready\ struct that provides a one-time marking mechanism for signaling when an entity is ready. The \Ready\ component ensures that multiple listeners can safely wait for a single initialization or readiness event, with corresponding tests verifying the behavior of the readiness gate.

internal/circuit · high confidence

Initial project scaffolding and repository configuration

The repository was initialized with essential project files, including a Makefile for build and test automation, a Go module definition, and standard documentation files (README, CONTRIBUTING, LICENSE, Code of Conduct). Additionally, a .gitignore file was added to exclude build artifacts and vendor directories from version control, while the previous docker-compose.yml was removed.

(repo-wide) · high confidence

Introduce Commander middleware framework and Zipkin integration

Added a new middleware system for the Commander library, allowing users to attach behavior to consume and produce events. The diff introduces the core middleware interfaces and client implementation, along with built-in middlewares for recovery, throttling, and timeouts. Additionally, a full Zipkin integration is provided, enabling distributed tracing for messages by automatically creating and managing spans for consume and produce operations, complete with header propagation and context management.

middleware · high confidence

Introduce internal metadata and options configuration

Added new internal packages for managing metadata context propagation and server/group/handler configuration. The \internal/metadata\ package provides context helpers to store and retrieve headers, retries, parent timestamps, and parent IDs. The \internal/options\ package introduces a codec interface with JSON and default no-op implementations, along with configuration structs for server, group, and handler options, including topic definitions.

internal/metadata, internal/options · high confidence

Introduced core type interfaces and message handling structures

Added new internal type definitions that establish the foundational interfaces and structures for the messaging system. This includes the Consumer and Producer interfaces for message handling, the Dialect interface for protocol-specific logic, and the Topic interface for managing message routing. The Message type has been expanded with explicit Ack and Nack states to signal message resolution, alongside StatusCode and MessageType enums. Additionally, the Writer interface and Handler types have been introduced to support group-based message production and processing.

internal/types · high confidence

Removals

Removal of the Commander service

The Commander service, which previously consumed commands from a Kafka topic and processed them, has been removed from the codebase. This eliminates the associated Kafka consumer/producer logic and command struct definitions.

service/commander · high confidence

Removed Dockerfile and main.go entry point

The service's Dockerfile and the main.go entry point have been removed from the codebase. This eliminates the previous method of building and running the service via a Go-based Docker container, indicating a shift away from the prior containerized deployment approach.

service · high confidence

Removed legacy REST service implementation

The legacy REST service implementation has been removed from the codebase. This includes the Dockerfile for building the Go service, the main entry point, and all associated handler, response, and commander logic. This change eliminates the previous HTTP server and Kafka integration code that was previously located in the rest directory.

rest · high confidence

Dependencies

Add Go module files for example projects

Added go.mod and go.sum files for the kafka, mock, mock-multiple-groups, and zipkin example projects, establishing their Go module definitions and dependency graphs. The root go.mod was also added, defining the commander module and its dependencies including Shopify/sarama, gofrs/uuid, golangci-lint, zipkin-go, logrus, and x/tools.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 62 → 63 (+1.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (-0.1)
  • Architecture 100 → 98 (-1.5)
  • Maturity 53 → 53 (+0.0)
  • Readiness 57 → 57 (+0.5)
  • Security 70 → 80 (+9.1)

Resolved (13)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (13 lines × 2) (examples/kafka/main.go)
  • Duplicated block (15 lines × 2) (dialects/kafka/connectionstring.go)
  • Duplicated block (23 lines × 2) (group.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • The connection-string table lists the required flags (brokers, version) but initial-offset is marked 'false' and defaults to newest with no description. (dialects/kafka/README.md)
  • dormant codebase — no living knowledge left to concentrate

New (38)

  • Critical CVE: [GHSA redacted] (go.sum)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (12–13 lines × 3) (examples/kafka/main.go)
  • Duplicated block (15 lines × 2) (examples/kafka/main.go)
  • Duplicated block (17 lines × 2) (dialects/kafka/connectionstring.go)
  • Duplicated block (23 lines × 2) (group.go)
  • Duplicated block (8 lines × 2) (examples/kafka/main.go)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.sum)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.sum)
  • Medium CVE: [GHSA redacted] (go.sum)
  • Medium CVE: GO-2021-0142 (go.mod)
  • Medium CVE: GO-2026-6179 (go.sum)
  • Medium: security finding (details withheld)
  • …and 18 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jeroenrinzema/commander was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 8553e17ecfeaa33f207260611a92dc2bb53fe379 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.