Skip to content
CAI
Software that uses CAICheck a score

kigawas/clean-axum

65.2

Adequate · 21 September 2026

917

lines of production code

Rust

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add API documentation for the new Blog endpoint

The system now includes OpenAPI documentation for the Blog API, exposing endpoints for listing and creating blogs. This is part of a broader update to the documentation module that also includes Swagger UI and Scalar interfaces for the Root and User APIs, allowing users to explore the full API surface interactively.

doc · high confidence

Add blog domain model and API support

Introduced a new blog domain model, including the database entity, request parameters with validation, query filters, and OpenAPI schema definitions. The user model was updated to include a one-to-many relationship with blog posts, and both user and blog schemas now implement OpenAPI schema generation for API documentation.

models · high confidence

Added database migration for the Blog entity

The application now includes a database migration that creates a 'Blog' table with fields for id, authorId, title, and content, and establishes a foreign key relationship to the existing 'User' table. This migration is registered in the migration list, ensuring the schema is updated to support blog-related data.

migration · high confidence

Added utility functions and testing helpers

The utils module now includes database migration and file creation helpers, alongside a testing framework that provides functions to make HTTP requests and set up test databases.

utils · high confidence

Behavioural changes

Add prefork and shuttle runtime support

The application now supports two distinct runtime environments. A new \src/shuttle.rs\ module provides a Shuttle deployment target, while \src/tokio.rs\ introduces a preforking mode that spawns multiple worker processes to handle requests, alongside a standard single-process mode. The \src/main.rs\ entry point is updated to conditionally initialize logging and dispatch to either the Shuttle or Tokio/prefork execution paths based on feature flags.

src · high confidence

Revamped error handling and request validation in the API

The API now uses a centralized error handling system that converts internal and external errors into consistent JSON responses with appropriate HTTP status codes. Request bodies are validated using the \Valid\ extractor, which ensures that invalid or missing data returns a 422 Unprocessable Entity with detailed validation errors, rather than a generic 500 or 400 error. This change applies to all endpoints, including the new \/blogs\ and existing \/users\ routes, ensuring uniform error responses across the application.

api · high confidence

Reworks application structure and adds blog persistence

The application's internal structure has been reorganized: the 'services' module has been renamed to 'persistence' to better reflect its role in data access, and a new 'error' module has been introduced to centralize error handling, specifically defining a 'UserError' type. Additionally, a new 'blog' persistence layer has been added, providing functions to search and create blog posts, while the user persistence layer has been updated to use 'CreateUserParams' and includes a new 'get\_user' function. Configuration now supports a 'prefork' boolean setting, and the state management has been updated to use 'sea\_orm::DatabaseConnection' directly.

app/src · medium confidence

Test coverage

Add integration tests for API and persistence layers

Added new test files in the \tests\ directory to cover the application's API endpoints and persistence logic. The \tests/api\ module includes tests for blog, root, and user endpoints, verifying status codes and response bodies. The \tests/app\ module includes tests for blog and user persistence operations, ensuring that database interactions return the expected results.

tests · high confidence

Dependencies

Update workspace dependencies and add new crates

The workspace dependencies have been updated, including axum to v0.8.4, tower to v0.5.2, sea-orm to v1.1.12, serde to v1.0.219, serde\_json to v1.0.140, tracing to v0.1.41, utoipa to v5.4.0, and validator to v0.20.0. Additionally, the workspace now includes new crates for documentation (doc) and utilities (utils), and the app crate now depends on sea-orm.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 65 (+3.7)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-1.2)
  • Architecture 100 → 80 (-20.1)
  • Maturity 60 → 60 (+0.0)
  • Readiness 66 → 67 (+1.5)
  • Security 49 → 60 (+11.3)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (31)

  • Build action pinned to a mutable branch
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low vulnerability: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: RUSTSEC-2023-0071 (Cargo.lock)
  • Medium CVE: RUSTSEC-2025-0055 (Cargo.lock)
  • Medium advisory (unmaintained): RUSTSEC-2025-0052 (Cargo.lock)
  • Medium advisory (unmaintained): RUSTSEC-2026-0173 (Cargo.lock)
  • Medium advisory (unsound): RUSTSEC-2026-0097 (Cargo.lock)
  • Medium advisory (unsound): RUSTSEC-2026-0134 (Cargo.lock)
  • Medium advisory (unsound): RUSTSEC-2026-0135 (Cargo.lock)
  • …and 11 more

New (35)

  • Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (8 lines × 2) (api/src/routers/blog.rs)
  • Duplicated block (8 lines × 2) (api/src/routers/blog.rs)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low vulnerability: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: [GHSA redacted] (Cargo.lock)
  • Medium CVE: RUSTSEC-2023-0071 (Cargo.lock)
  • Medium CVE: RUSTSEC-2025-0055 (Cargo.lock)
  • …and 15 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kigawas/clean-axum was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5c3e9c66bfeeb00fa8cd13b79e9e56b4ea9ebf16 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.