Skip to content
CAI
Software that uses CAICheck a score

kcmvp/gob

56.1

Adequate · 29 July 2026

879

lines of production code

Go

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add DBO CLI tool for database scaffolding and code generation

Introduces a new command-line interface (CLI) for database operations, including commands to initialize project scaffolding, generate ER diagrams and database schemas, and set up database configurations for MySQL, PostgreSQL, and SQLite. The change adds Go source files for the CLI actions (init, generate, repository/service generation), templates for configuration and code generation, and metadata files defining type mappings and database drivers.

dbo · high confidence

Introduce gbc as a Go project bootstrapping and build tool

The project introduces \gbc\, a command-line tool designed to bootstrap and manage Go projects, similar to Maven or Gradle in the Java ecosystem. It provides a plugin-based build system where tools like \golangci-lint\ and \gotestsum\ are configured as plugins in a \gob.yaml\ file. The tool supports commands for initialization, building, testing, linting, and dependency management, and automatically sets up git hooks for code quality checks.

(repo-wide) · high confidence

Introduce plugin and scaffold management commands

Adds new internal commands for managing project scaffolding and build plugins. The \scaffold\ package introduces \init\ and \dbo\ commands to initialize project templates and generate database objects, supported by new resource files (\modules.json\, \build.yaml\, \.golangci.yaml\) that define available modules and linting configurations. Additionally, the \builder\ package adds a \plugin\ command to manage build plugins (e.g., golangci-lint, gotestsum) and an \exec\ command to run them, alongside a \dep\ command to visualize project dependencies. These changes replace the previous \internal/project.go\ implementation, which is removed.

internal · high confidence

Introduce project management, plugin execution, and progress tracking capabilities

Added new Go source files in the project package to support project initialization, plugin management, and command execution. The \project.go1\ file introduces a \Project\ struct that loads Go module information, manages configuration files, and tracks package metadata. The \plugin.go1\ file adds a \Plugin\ type with logic to download, validate, and execute plugins, including shell script generation and binary installation. The \dependency.go1\ file provides a \Dependency\ struct and logic to resolve and list project dependencies, including their latest versions and transitive dependencies. The \pty\_writer.go1\ file implements a terminal writer that captures and formats command output with color and progress indicators. The \progress.go1\ file adds a spinner progress bar for command execution. Additionally, test files \project\_test.go1\ and \plugin.go\_test.go1\ are added to verify project and plugin functionality. Resource files \.golangci.yaml\ and \artifact.json\ are included to configure linting and define built-in plugins and web frameworks.

project · high confidence

Removals

Removal of legacy CLI command implementations

The \cmd\ package has removed the previous implementation of the CLI commands, specifically deleting \buillder.go\, \gen.go\, \init.go\, and \root.go\. This eliminates the old command-line interface structure, including the \gob\ root command and its subcommands (\init\, \build\, \clean\, \test\, \lint\), effectively removing the existing user-facing CLI functionality from this location.

cmd · high confidence

Behavioural changes

Removal of the 'tool' package

The 'tool' package, which previously defined a 'Tool' struct and associated methods for managing tool configurations and installations, has been removed from the codebase.

tool · high confidence

Test coverage

Added test data fixtures for build configuration and coverage

Added new test data files to support testing infrastructure: a \build.yaml\ configuration defining lint and test plugins (golangci-lint, gotestsum), a \config.json\ specifying plugin aliases and dependencies, and a \cover.out\ file containing code coverage data for internal packages like hook, multiple\_writer, plugin, progress, and project. These files serve as reference data for the project's automated testing and build processes.

testdata · high confidence

Dependencies

Updated Go dependencies and tooling

The project's Go module dependencies have been updated, including upgrades to libraries such as github.com/fatih/color (v1.16.0 to v1.18.0) and github.com/spf13/cobra (v1.8.0 to v1.8.1). New dependencies like github.com/google/yamlfmt and github.com/kcmvp/buildtime have been added, while several older indirect dependencies (e.g., github.com/fsnotify/fsnotify, github.com/pelletier/go-toml/v2) have been removed or replaced. The Go version requirement has also been updated from 1.21.4 to 1.22.2.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 46 → 56 (+10.5)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

Lenses

  • Code Health 88 → 88 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 57 → 57 (+0.0)
  • Readiness 24 → 44 (+19.7)
  • Security 70 → 85 (+14.9)

Resolved (6)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Rotate the exposed credentials — git history can't be un-committed

New (8)

  • Coverage read from a committed report
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: GO-2024-2824 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kcmvp/gob was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 29e4ae2223dc492197f4a4b0fb4c701362710178 — the exact code this score is about.
  • Scored under rubric-2026.08.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.