Skip to content
CAI
Software that uses CAICheck a score

jpgsaraceni/suricate-bank

58.1

Adequate · 21 September 2026

2.8k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a banking API service that manages financial accounts and transfers. It provides capabilities to create and authenticate accounts, perform credit and debit transactions, and record transfer history. The application enforces business rules such as idempotency and positive transfer amounts, backed by PostgreSQL for persistence and Redis for caching and locking.

How it got here

2021 — core domain and infrastructure setup

7 changes.

This period focused on establishing the foundational architecture of the application, introducing domain entities, value objects, and use cases for accounts and transfers. Simultaneously, the project scaffolded essential tooling, including Docker configurations, a Makefile, and updated Go dependencies to support the new structure.

2022 — Initial API and database implementation

10 changes.

This period focused on building the core infrastructure for the Suricate Bank API, including PostgreSQL and Redis backends, authentication, and API endpoints. The work established the foundational services for account management, transfers, and idempotency, supported by comprehensive testing and structured logging.

Features

Add CPF validation and secure hash storage

Introduced new value objects for handling sensitive and identifying data: a CPF (Brazilian individual taxpayer registry) validator that verifies, masks, and scans Brazilian ID numbers, and a Secret wrapper for bcrypt-based password hashing with database scanning support.

app/vos/cpf, app/vos/hash · high confidence

Add account domain use cases for account management

Introduces new domain use cases for account operations, including creating accounts, fetching account lists, retrieving account details by ID, checking balances, and performing credit and debit transactions. Each use case is accompanied by comprehensive unit tests covering success paths, error handling, and edge cases.

app/domain/usecases/account · high confidence

Add database schema and repository layer for accounts and transfers

The application now includes the initial PostgreSQL schema and repository implementations for managing bank accounts and transfers. The database schema introduces an \accounts\ table to store user account details and a \transfers\ table to record transaction history. Corresponding Go repositories provide methods to create accounts, credit and debit balances, fetch account details by ID or CPF, and manage transfer records, all backed by comprehensive unit tests.

app/gateways/db/postgres/accounts · high confidence

Add transfer usecase with create and fetch capabilities

The application now includes a new transfer usecase that allows users to create new transfers and fetch existing ones. The implementation handles the core logic for debiting the origin account and crediting the destination account, including rollback mechanisms for failed operations. Additionally, a fetch function is provided to retrieve a list of all transfers. The change also introduces mock implementations for testing purposes.

app/domain/usecases/transfer · high confidence

Added Postgres test helper for integration testing

A new Go package, app/gateways/db/postgres/postgrestest, was added to provide a reusable helper for integration tests. This helper spins up a temporary Postgres 14 container via Docker, establishes a connection pool, and automatically applies database migrations from the local file system. It also includes a cleanup function to tear down the container and close the pool, simplifying the setup of a clean database state for each test case.

app/gateways/db/postgres/postgrestest · high confidence

Added Redis caching and locking capabilities for idempotent requests

The Redis gateway now includes new functions to cache HTTP responses and manage distributed locks for idempotency. Users benefit from improved reliability and performance, as responses can be stored in Redis to avoid redundant processing, and concurrent requests are managed via a locking mechanism that prevents duplicate operations. The implementation includes a connection pool, error handling, and comprehensive tests for these new features.

app/gateways/db/redis · high confidence

Added authentication and idempotency service layers

The app/services directory now includes a new auth package that implements user authentication by validating a CPF and secret against stored account data, returning a signed JWT token. Additionally, a new idempotency package has been introduced to manage request deduplication and response caching, providing mechanisms to lock, cache, and retrieve responses to ensure idempotent behavior for repeated requests.

app/services · high confidence

Added project scaffolding and configuration files

Introduced essential project configuration and tooling files to support development and deployment. This includes a Dockerfile for containerization, a docker-compose.yml for local service orchestration (PostgreSQL and Redis), and a Makefile with targets for linting, testing, and building. Additionally, environment variable templates (.env.example) and IDE-specific ignore rules (.golangci.yml, updated .gitignore) were added to standardize the development environment and enforce code quality.

(repo-wide) · high confidence

Initial launch of the Suricate Bank API

The application now starts as a complete API service, wiring together PostgreSQL and Redis backends with account and transfer use cases. Users can create accounts and perform idempotent transfers, with Swagger documentation and UI available at the root path.

cmd · high confidence

Introduce JWT-based authentication token generation and verification

Added a new \app/vos/token\ package that provides \Sign\ and \Verify\ functions for creating and validating JSON Web Tokens (JWTs). The \Sign\ function generates a signed token containing an account ID, while \Verify\ validates the token's signature and extracts the associated account ID. This enables stateless authentication flows where the server can issue and validate user identity via signed tokens.

app/vos/token · high confidence

Introduce Money value object for handling currency amounts

Added a new Money value object in the app/vos/money package to manage currency values in cents. This component provides safe methods for creating, adding to, and subtracting from monetary amounts, ensuring that negative values are rejected and insufficient funds are prevented. It also includes a BRL formatting utility for display purposes.

app/vos/money · high confidence

Introduce Zerolog-based structured logging infrastructure

Added a new logging implementation using the Zerolog library, providing structured, high-performance logging capabilities. This change introduces a configurable logging system that supports log levels, console output formatting, and error stack tracing, replacing or supplementing the previous logging mechanism.

app/infrastructure · high confidence

Introduce account and transfer domain entities with repository interfaces

The domain layer now includes new domain entities for accounts and transfers, each with their own error definitions and repository interfaces. The Account entity validates CPF and secret fields, initializes with a default balance, and provides ID parsing. The Transfer entity enforces that origin and destination accounts differ and that the transfer amount is positive. Both entities include mock repository implementations for testing purposes.

app/domain · high confidence

Introduce account, login, and transfer API endpoints

The API gateway now exposes HTTP handlers for creating accounts, fetching account lists, retrieving account balances, logging in, and creating/fetching transfers. This includes the request/response schemas, error payloads, and middleware for authentication, idempotency, and request logging. Tests are added for each handler to verify status codes, payload validation, and error handling.

app/gateways/api · high confidence

Postgres database connection and migration support

The application now establishes a connection pool to a PostgreSQL database and automatically applies embedded SQL migrations on startup. This ensures the database schema is up-to-date before the application begins processing requests.

app/gateways/db/postgres · high confidence

Behavioural changes

Application configuration via environment variables

The application now loads its configuration from environment variables, allowing runtime customization of the HTTP server port and host, database connection details, JWT settings, and Redis parameters. This replaces hardcoded defaults with values sourced from the environment, making the application more flexible for different deployment environments like Heroku.

config · high confidence

Dependencies

Update Go dependencies and module path

The project's Go module path was changed from 'bank' to 'github.com/jpgsaraceni/suricate-bank'. Several dependencies were updated to newer versions: github.com/golang-jwt/jwt/v4 to 4.4.1, github.com/swaggo/swag to 1.8.2, github.com/swaggo/http-swagger to 1.2.8, github.com/jackc/pgconn to 1.12.1, and github.com/jackc/pgx/v4 to 4.16.1. The go.sum file was also updated to reflect these changes.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 59 → 58 (-0.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.2)
  • Architecture 100 → 74 (-25.9)
  • Maturity 50 → 50 (+0.0)
  • Readiness 54 → 52 (-1.3)
  • Security 57 → 67 (+10.7)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (31)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (8 lines × 2) (app/vos/cpf/cpf.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 11 more

New (57)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: golang.org/x/crypto
  • Documentation: no usage examples (README.md)
  • Duplicated block (12 lines × 2) (app/gateways/api/http/handlers/accounts/fetch.go)
  • Duplicated block (7 lines × 2) (app/vos/cpf/cpf.go)
  • Duplicated block (8 lines × 2) (app/domain/usecases/account/fetch_accounts.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 37 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jpgsaraceni/suricate-bank was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6fddfe00beaa4040157436893bd347bf79854dad — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.