Skip to content
CAI
Software that uses CAICheck a score

jessicatarra/refactoring-greenlight

56.0

Weak · 21 September 2026

12.5k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a modular monolith application that manages user authentication, authorization, and movie data. It exposes functionality through both HTTP and gRPC interfaces, handling user registration, account activation, and token validation. The architecture consolidates previously separate services into a single executable, supported by internal packages for configuration, error handling, and background tasks.

Features

Added gRPC service definitions for authentication

The API now includes generated Go code for a new gRPC service called AuthGRPCService. This service exposes two unary RPCs: ValidateAuthToken, which accepts a token and returns user details, and UserPermission, which checks user permissions. These changes introduce the underlying communication contract for authentication and authorization, enabling clients to interact with the system via gRPC.

api · high confidence

Added go-sqlmock and go-spew vendor dependencies

The vendor directory now includes the go-sqlmock library, providing a mock implementation of the Go SQL driver for testing database interactions without a real database connection. This includes support for Go 1.8+ context-based queries, ping monitoring, and custom query matchers. Additionally, the go-spew library has been added to the vendor directory, providing deep equality checking and pretty-printing capabilities for Go data structures.

vendor · high confidence

Introduce auth microservice with user registration, activation, and authentication endpoints

The auth microservice now provides HTTP and gRPC interfaces for user registration, account activation, and authentication token creation. The application layer implements use cases for creating users, activating accounts via email tokens, validating authentication tokens, and checking user permissions. HTTP handlers expose routes for user creation, activation, and authentication token generation, while gRPC services expose token validation and permission checks. Repository implementations handle user and token data access, and mock implementations are provided for testing.

ms · high confidence

Migrate cmd/api to cmd/mono and implement modular monolith architecture

The application entry point and core logic have been moved from cmd/api to cmd/mono, introducing a modular monolith structure. This includes a new main.go that initializes the application, a monolith.go that manages module lifecycle, and a server.go that starts the HTTP server. The routes.go file defines HTTP endpoints for movie management and health checks, while middleware.go adds authentication and permission checks. Helper functions and context handling have been updated to use the new package structure and error handling.

cmd/mono · high confidence

Behavioural changes

Refactor application entry point to modular monolith architecture

The application's entry point has been refactored from a single 'api' binary to a 'mono' binary, supporting a modular monolith architecture. The Dockerfile and docker-compose.yaml have been updated to build and run the new 'mono' executable, exposing port 8082 in addition to 8080. The Makefile now includes targets for the 'mono' build and run commands, and generates documentation for the 'cmd/mono' and 'ms/auth/internal' directories. Additionally, a new 'generate/auth/mocks' target has been added to generate mocks for the auth module's domain and service layers.

(repo-wide) · high confidence

Refactored internal packages and removed legacy database models

The internal package structure has been refactored, introducing new modules for concurrent background tasks, configuration, error handling, middleware, password hashing, and validation. Specifically, the codebase now includes dedicated packages for handling background tasks (internal/concurrent), application configuration (internal/config), structured error reporting (internal/errors), HTTP middleware (internal/middleware), password hashing (internal/password), and request/response handling (internal/request, internal/response). Additionally, the legacy database models for users, tokens, and permissions have been removed from the internal/database package, leaving only the movie model, while the old jsonlog and database/user files were deleted.

internal · high confidence

Removed legacy API server implementation

The legacy HTTP API server, middleware, and handlers have been removed from the codebase. This includes the main entry point, error handling, middleware chain, route definitions, and specific handlers for user registration, authentication, and account activation. A simple CORS example has been updated to point to the new server port 8080.

cmd/api · high confidence

Dependencies

Updated Go dependencies and added new libraries

The project's Go dependencies have been updated and expanded. New dependencies added include go-sqlmock, golang/protobuf, google.golang.org/grpc, and golang.org/x/exp. Additionally, versions of existing packages like testify, protobuf, and text have been upgraded, while justinas/alice has been removed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 56 → 56 (-0.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (-0.0)
  • Architecture 100 → 97 (-3.2)
  • Maturity 41 → 41 (+0.0)
  • Readiness 49 → 45 (-3.4)
  • Security 77 → 83 (+5.9)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (21)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (cmd/mono/helpers.go)
  • Duplicated block (15 lines × 2) (cmd/mono/movies.go)
  • Duplicated block (16 lines × 3) (ms/auth/internal/infrastructure/repositories/user_repository.go)
  • Duplicated block (7 lines × 2) (cmd/examples/cors/preflight/main.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2023-2041 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Test reliability not included
  • complexity unreadable for .go — churn × complexity hotspots could not be measured
  • …and 1 more

New (43)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: golang.org/x/exp
  • Deprecated module: github.com/golang/protobuf
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (cmd/mono/helpers.go)
  • Duplicated block (16 lines × 2) (cmd/mono/movies.go)
  • Duplicated block (19–20 lines × 3) (ms/auth/internal/infrastructure/repositories/user_repository.go)
  • Duplicated block (31–38 lines × 2) (cmd/mono/helpers.go)
  • Duplicated block (5 lines × 2) (cmd/mono/server.go)
  • Duplicated block (9 lines × 2) (cmd/mono/movies.go)
  • Duplicated block (9–10 lines × 2) (cmd/examples/cors/preflight/main.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 23 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jessicatarra/refactoring-greenlight was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 70e5ad204efd088182a1d18036cc53afacd3c6ba — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.