Skip to content
CAI
Software that uses CAICheck a score

kcmvp/archunit

70.3

Strong · 21 September 2026

3.3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an architectural testing library for Go that enforces codebase rules and best practices. It provides a declarative API to define and validate constraints on packages, types, and functions, ensuring structural integrity. The project also includes internal utilities for parsing Go source code and a custom test suite wrapper for enhanced logging and assertions.

Features

ArchUnit for Go: Initial release of architectural testing library

The project introduces \archunit\, a Go library for enforcing architectural rules and best practices. The release establishes the core API for defining and validating architectural constraints, including a fluent, declarative interface for selecting code units (layers, packages, types) and applying rules (e.g., \ShouldNotRefer\, \ShouldOnlyRefer\). It includes a comprehensive set of pre-defined global rules for common Go best practices (naming, package structure, API design) and supports a 'Code as Promotion' paradigm for AI-guided development. The initial commit also adds the Apache 2.0 license and project documentation.

(repo-wide) · high confidence

Introduce custom test suite wrapper with automatic log file generation

Added suite/suite.go which provides a custom testing.T wrapper and an ArchSuite base class. This allows test suites to automatically write logs to dedicated files in a 'target' directory, particularly capturing logs for failed tests. The implementation wraps standard testing functionality to support enhanced logging and assertion methods.

suite · high confidence

Introduce internal artifact parsing for Go source code

Added internal/artifact.go and internal/utils/utils.go to parse Go source files and extract metadata about packages, functions, types, and variables. The new Artifact struct and associated methods (e.g., Arch, Packages, Package, Types) enable the application to inspect the project's codebase, including support for subfolders and wildcard patterns. Corresponding tests in internal/artifact\_test.go validate the parsing of constants, functions, imports, and type methods against golden JSON files.

internal · high confidence

Introduce service layer interfaces and implementations for user and login operations

The service layer now includes a \UserService\ with methods to retrieve users by ID, name, and first name, alongside a \NameService\ interface and its implementations (\NameServiceImpl\, \FullNameImpl\). Additionally, external service definitions are added for login (\LoginService\ in v1 and v2) and third-party storage (\S3\), establishing the internal service architecture.

internal/sample/service · medium confidence

Behavioural changes

Refactor repository layout and introduce constants

The repository package is reorganized with new files: constants.go defines FF type and F1, F2, F3 constants; ext/user\_ext.go adds UserRepositoryExt; and user\_repository.go is moved to internal/sample/repository, updating its import path to github.com/kcmvp/archunit/internal/sample/model and adding Mast and Slave string constants.

internal/sample/repository · medium confidence

Refactored internal package layout and added new controller components

The codebase has been reorganized by moving existing model and view files into the internal directory structure, while introducing new controller implementations. Specifically, a new LoginController and AppController are added to handle login and application logic respectively, alongside a new VUtil package for view utilities. These changes reflect a structural refactor to better organize internal components.

internal/sample/controller · medium confidence

Removed legacy controller and service implementations

The sample application's legacy code has been removed. Specifically, the \LoginController\ and \AppController\ in the \sample/controller\ directory, along with the \UserService\ in the \sample/service\ directory, have been deleted. This cleanup removes unused or outdated components related to user login and application control, simplifying the sample structure.

sample · high confidence

Dependencies

Updated Go version and upgraded dependencies

The project has been upgraded to Go 1.22.2. Several dependencies have been updated to newer versions: github.com/samber/lo to v1.51.0, github.com/samber/mo to v1.15.0, github.com/stretchr/testify to v1.9.0, and golang.org/x/tools to v0.22.0. Additionally, new dependencies such as github.com/fatih/color have been added, and various indirect dependencies have been updated or replaced.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 68 → 70 (+2.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 80 → 86 (+5.6)
  • Architecture 100 → 100 (-0.3)
  • Maturity 72 → 73 (+1.0)
  • Readiness 57 → 58 (+1.0)
  • Security 85 → 90 (+5.6)

Resolved (21)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (rule.go)
  • Duplicated block (11 lines × 2) (rule.go)
  • Duplicated block (12 lines × 2) (rule.go)
  • Duplicated block (12 lines × 2) (rule.go)
  • Duplicated block (22 lines × 2) (rule.go)
  • Duplicated block (7 lines × 2) (object.go)
  • Duplicated block (8 lines × 2) (global.go)
  • Duplicated block (8 lines × 2) (internal/artifact.go)
  • Duplicated block (8 lines × 2) (object.go)
  • Duplicated block (9 lines × 2) (object.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: GO-2025-4006 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • No exposed public API
  • Test reliability not included
  • …and 1 more

New (48)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (global.go)
  • Duplicated block (10 lines × 2) (rule.go)
  • Duplicated block (10 lines × 2) (rule.go)
  • Duplicated block (10 lines × 2) (rule.go)
  • Duplicated block (11 lines × 2) (global.go)
  • Duplicated block (11 lines × 2) (object.go)
  • Duplicated block (11 lines × 2) (rule.go)
  • Duplicated block (13 lines × 2) (global.go)
  • Duplicated block (13 lines × 2) (rule.go)
  • Duplicated block (17–18 lines × 2) (rule.go)
  • Duplicated block (32–33 lines × 2) (rule.go)
  • Duplicated block (5 lines × 2) (global.go)
  • Duplicated block (6 lines × 2) (rule.go)
  • Duplicated block (8 lines × 2) (internal/artifact.go)
  • Duplicated block (8 lines × 2) (object.go)
  • Duplicated block (8 lines × 2) (object.go)
  • Duplicated block (9 lines × 4) (rule.go)
  • High: security finding (details withheld)
  • …and 28 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kcmvp/archunit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 864f3bb7803f1ce4b72eaeddbfa1654dfce2adb3 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.