kirklin/qzone-history
44.1
Weak · 21 September 2026
1.9k
lines of production code
Go
primary language
4
measurements over time
What this system is
Features
Add QR code login flow and database persistence layer
Users can now log in via a browser-based QR code scan, with the system automatically opening a local server to display the code and detect login status. The application also introduces a new persistence layer using SQLite (via GORM) to store user, moment, and comment data, alongside utility functions for generating authentication tokens and processing HTML content.
pkg · high confidence
Add main entry point for the Qzone History application
The application now includes a main.go file that initializes and runs the core components, including database connections, repositories, use cases, and the application runner, providing a complete entry point for the Qzone History tool.
cmd · high confidence
Initial application entry point and core orchestration logic
A new \App\ struct and its \Run\ method have been introduced in \internal/delivery/app/app.go\. This change implements the main application lifecycle, which handles authentication (including QR code-based login flows), fetches user activity records, triggers data reconstruction for moments and board messages, and exports user data to JSON. This serves as the central orchestrator for the application's core features.
internal/delivery · high confidence
Initial domain entity definitions for QQ space features
The application now includes the foundational domain models for QQ space interactions, including User, Moment, Activity, Comment, Friend, and BoardMessage. These entities define the core data structures for managing user profiles, social feeds, and messaging, establishing the data layer for the domain.
internal/domain/entity · high confidence
Initial version string added to the application
A new version variable has been introduced in the codebase, initializing the qzone-history application with a default version string of 'v0.0.1'. This allows the application to report its current version, which can be overridden at build time using ldflags.
version · high confidence
Introduce configuration loading and persistence layer for Qzone data
The application now supports loading configuration from a YAML file with fallback to sensible defaults for database and Qzone API endpoints. A new persistence layer has been added, implementing repository interfaces for activities, board messages, friends, moments, and users, enabling data storage and retrieval via the database.
internal/infrastructure · high confidence
Introduce usecase layer for Qzone history data
A new internal usecase layer has been added to the application, providing structured Go implementations for managing user authentication, activity tracking, moment and board message handling, friend management, data export, and data reconstruction. These components bridge the domain entities and repositories with the Qzone API infrastructure, enabling features such as login status checks, activity fetching and saving, moment creation and interaction, board message retrieval, friend status checks, JSON data export, and reconstructing moments and board messages from raw activity data.
internal/usecase · high confidence
Introduced domain use-case interfaces for core features
Added new interface definitions for the application's domain layer, establishing the contracts for user, authentication, activity, friend, moment, board message, export, and reconstruction use cases. These interfaces define the operations available for each domain, such as retrieving user information, managing login states, fetching social activities, and exporting data, providing the foundation for the application's business logic.
internal/domain/usecase · high confidence
Introduces domain repository interfaces for core entities
Added new repository interfaces for Activity, BoardMessage, Friend, Moment, and User entities. These define the storage contracts for importing, inserting, and querying data, establishing the data access layer for the application's domain models.
internal/domain/repository · high confidence
Dependencies
Updated Go dependencies and runtime version
The project has been upgraded to Go 1.25.2 and updated several dependencies to newer versions, including goquery, viper, gorm, and the sqlite driver. Additionally, the codebase now includes the progress bar library (progressbar/v3) and related indirect dependencies, while removing older versions of packages like go-sqlite3 and gorm.io/driver/sqlite.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 41 → 44 (+3.0)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 98 → 97 (-0.4)
- Architecture 100 → 87 (-13.5)
- Maturity 45 → 40 (-4.6)
- Readiness 28 → 37 (+8.6)
- Security 59 → 71 (+11.6)
- Domain Modelling 51 → 58 (+7.5)
- Accessibility 50 → 46 (-3.9)
Resolved (19)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2025-4007 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- No exposed public API
- early-stage repository — too little history to judge knowledge freshness
- git history depth insufficient
- git history depth insufficient
- single-maintainer — knowledge-concentration (bus factor) risk
New (23)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (5 lines × 2) (internal/infrastructure/persistence/board_message_repository.go)
- Duplicated block (8 lines × 2) (internal/infrastructure/persistence/board_message_repository.go)
- Duplicated block (8 lines × 2) (internal/infrastructure/qzone_api/qzone_api.go)
- Duplicated block (8 lines × 2) (internal/infrastructure/qzone_api/qzone_api.go)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2025-4007 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No ADRs found
- No dependency advisory monitoring
- Outdated: github.com/PuerkitoBio/goquery
- Outdated: github.com/schollz/progressbar/v3
- Outdated: gorm.io/gorm
- …and 3 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
kirklin/qzone-history was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 949e95282a67b4ef62122a79439c029134a5b149 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.