Skip to content
CAI
Software that uses CAICheck a score

kienmatu/togo

52.5

Adequate · 21 September 2026

756

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add configuration loading for application settings

The application now loads configuration values such as the server port, JWT secret, and database connection URL from environment variables or a .env file. This enables externalizing sensitive settings and allows the application to be configured without code changes.

config · high confidence

Add todos CRUD endpoints and enforcement of per-user record limits

The todos module now exposes HTTP handlers for creating, retrieving, and listing todos, wired via new route definitions. The use case layer enforces a per-user record limit by checking the user's current count against their quota before allowing new todos to be created. A repository layer with GORM and a corresponding test suite are also introduced to support these operations.

internal/todos · high confidence

Added JWT authentication middleware

A new JWT validation middleware has been introduced to the application's middleware stack. This addition enables the system to validate Bearer tokens from the Authorization header, verifying the token's integrity and extracting the user ID for subsequent request processing. If validation fails or the header is missing, the middleware returns an appropriate HTTP error, ensuring that only authenticated users can access protected routes.

internal/middlewares · high confidence

Initialize Go API server entry point

Added the main entry point for the API server, which initializes configuration, database connections, and starts the server. This establishes the application's bootstrap process, integrating with the existing config and database packages to launch the HTTP server.

cmd · high confidence

Introduce user registration and authentication endpoints

The application now exposes HTTP endpoints for user registration and sign-in. Users can create an account via a POST to /api/v1/auth/register, which accepts a username, password, and a limit for records per user. Signing in via POST /api/v1/auth/login returns a JWT token. The implementation includes the necessary handlers, use cases, and repository layers to support these features.

internal/auth · high confidence

New HTTP and validation utilities

Added new utility functions for handling HTTP requests and struct validation. The \utils/http.go\ file introduces a \ReadRequest\ function that binds and validates incoming request bodies using the Echo framework. Additionally, \utils/validator.go\ provides a reusable \ValidateStruct\ function leveraging the go-playground/validator library, while \utils/random.go\ adds a helper for generating random strings.

utils · high confidence

Behavioural changes

Added database connection handlers for MongoDB and PostgreSQL

The application now includes initial database integration code for both MongoDB and PostgreSQL. The new db/mongo.go file provides a singleton session manager for MongoDB using the mgo.v2 driver, while db/postgres.go implements a GORM-based connection handler for PostgreSQL that supports automatic schema migration for User and Todo models.

db · high confidence

Test coverage

Added end-to-end integration tests for the registration flow

Added an end-to-end test suite in the integration-tests directory that verifies the user registration endpoint. The test spins up the server, sends a registration request, and validates the response structure and status code.

integration-tests · high confidence

Dependencies

Initialize Go module with core dependencies

The project is initialized as a Go module (kienmatu/go-todos) using Go 1.17, establishing the project's dependency graph. This includes direct dependencies for the HTTP server (gorilla/handlers, labstack/echo/v4), security (golang.org/x/crypto), and database access (gorm.io/gorm, gorm.io/driver/postgres), alongside testing and utility libraries (stretchr/testify, go-test/deep).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 51 → 53 (+2.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.3)
  • Architecture 69 → 69 (+0.0)
  • Maturity 63 → 63 (+0.0)
  • Readiness 26 → 32 (+6.0)
  • Security 89 → 78 (-11.2)
  • Domain Modelling 87 → 87 (+0.0)

Resolved (8)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • The 'What next ?' section lists backlog items like role/permission validation and test additions but no further content appears in the clipped body. (README.md)
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness

New (34)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/Rosaniline/gorm-ut
  • Dependency pinned to a stale untagged commit: golang.org/x/crypto
  • Dependency pinned to a stale untagged commit: gopkg.in/mgo.v2
  • Documentation: no usage examples (README.md)
  • Duplicated block (8 lines × 2) (internal/auth/repository/repository.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Low IaC: DS-0026 (Dockerfile)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2022-0969 (go.mod)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • …and 14 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kienmatu/togo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 429d3eda1adb90d69b2c2fd2e6949f6a28ab7d49 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.