jessicatarra/refactoring-greenlight
56.0
Weak · 21 September 2026
12.5k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a modular monolith application that manages user authentication, authorization, and movie data. It exposes functionality through both HTTP and gRPC interfaces, handling user registration, account activation, and token validation. The architecture consolidates previously separate services into a single executable, supported by internal packages for configuration, error handling, and background tasks.
Features
Added gRPC service definitions for authentication
The API now includes generated Go code for a new gRPC service called AuthGRPCService. This service exposes two unary RPCs: ValidateAuthToken, which accepts a token and returns user details, and UserPermission, which checks user permissions. These changes introduce the underlying communication contract for authentication and authorization, enabling clients to interact with the system via gRPC.
api · high confidence
Added go-sqlmock and go-spew vendor dependencies
The vendor directory now includes the go-sqlmock library, providing a mock implementation of the Go SQL driver for testing database interactions without a real database connection. This includes support for Go 1.8+ context-based queries, ping monitoring, and custom query matchers. Additionally, the go-spew library has been added to the vendor directory, providing deep equality checking and pretty-printing capabilities for Go data structures.
vendor · high confidence
Introduce auth microservice with user registration, activation, and authentication endpoints
The auth microservice now provides HTTP and gRPC interfaces for user registration, account activation, and authentication token creation. The application layer implements use cases for creating users, activating accounts via email tokens, validating authentication tokens, and checking user permissions. HTTP handlers expose routes for user creation, activation, and authentication token generation, while gRPC services expose token validation and permission checks. Repository implementations handle user and token data access, and mock implementations are provided for testing.
ms · high confidence
Migrate cmd/api to cmd/mono and implement modular monolith architecture
The application entry point and core logic have been moved from cmd/api to cmd/mono, introducing a modular monolith structure. This includes a new main.go that initializes the application, a monolith.go that manages module lifecycle, and a server.go that starts the HTTP server. The routes.go file defines HTTP endpoints for movie management and health checks, while middleware.go adds authentication and permission checks. Helper functions and context handling have been updated to use the new package structure and error handling.
cmd/mono · high confidence
Behavioural changes
Refactor application entry point to modular monolith architecture
The application's entry point has been refactored from a single 'api' binary to a 'mono' binary, supporting a modular monolith architecture. The Dockerfile and docker-compose.yaml have been updated to build and run the new 'mono' executable, exposing port 8082 in addition to 8080. The Makefile now includes targets for the 'mono' build and run commands, and generates documentation for the 'cmd/mono' and 'ms/auth/internal' directories. Additionally, a new 'generate/auth/mocks' target has been added to generate mocks for the auth module's domain and service layers.
(repo-wide) · high confidence
Refactored internal packages and removed legacy database models
The internal package structure has been refactored, introducing new modules for concurrent background tasks, configuration, error handling, middleware, password hashing, and validation. Specifically, the codebase now includes dedicated packages for handling background tasks (internal/concurrent), application configuration (internal/config), structured error reporting (internal/errors), HTTP middleware (internal/middleware), password hashing (internal/password), and request/response handling (internal/request, internal/response). Additionally, the legacy database models for users, tokens, and permissions have been removed from the internal/database package, leaving only the movie model, while the old jsonlog and database/user files were deleted.
internal · high confidence
Removed legacy API server implementation
The legacy HTTP API server, middleware, and handlers have been removed from the codebase. This includes the main entry point, error handling, middleware chain, route definitions, and specific handlers for user registration, authentication, and account activation. A simple CORS example has been updated to point to the new server port 8080.
cmd/api · high confidence
Dependencies
Updated Go dependencies and added new libraries
The project's Go dependencies have been updated and expanded. New dependencies added include go-sqlmock, golang/protobuf, google.golang.org/grpc, and golang.org/x/exp. Additionally, versions of existing packages like testify, protobuf, and text have been upgraded, while justinas/alice has been removed.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 56 → 56 (-0.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (-0.0)
- Architecture 100 → 97 (-3.2)
- Maturity 41 → 41 (+0.0)
- Readiness 49 → 45 (-3.4)
- Security 77 → 83 (+5.9)
- Domain Modelling 100 → 100 (+0.0)
Resolved (21)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (cmd/mono/helpers.go)
- Duplicated block (15 lines × 2) (cmd/mono/movies.go)
- Duplicated block (16 lines × 3) (ms/auth/internal/infrastructure/repositories/user_repository.go)
- Duplicated block (7 lines × 2) (cmd/examples/cors/preflight/main.go)
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2023-2041 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- Medium IaC: CKV_DOCKER_3 (Dockerfile)
- No exposed public API
- Test reliability not included
- complexity unreadable for .go — churn × complexity hotspots could not be measured
- …and 1 more
New (43)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: golang.org/x/exp
- Deprecated module: github.com/golang/protobuf
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (cmd/mono/helpers.go)
- Duplicated block (16 lines × 2) (cmd/mono/movies.go)
- Duplicated block (19–20 lines × 3) (ms/auth/internal/infrastructure/repositories/user_repository.go)
- Duplicated block (31–38 lines × 2) (cmd/mono/helpers.go)
- Duplicated block (5 lines × 2) (cmd/mono/server.go)
- Duplicated block (9 lines × 2) (cmd/mono/movies.go)
- Duplicated block (9–10 lines × 2) (cmd/examples/cors/preflight/main.go)
- High CVE: [GHSA redacted] (go.mod)
- High IaC: WD-COMPOSE-0002 (docker-compose.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 23 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
jessicatarra/refactoring-greenlight was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 70e5ad204efd088182a1d18036cc53afacd3c6ba — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.