Skip to content
CAI
Software that uses CAICheck a score

kosatnkn/catalyst

62.8

Weak · 21 September 2026

1.1k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based microservice template implementing Clean Architecture, designed to scaffold and manage account-related domain logic. It provides a complete infrastructure layer with dependency injection, automated build metadata, and database readiness probes. The architecture supports multiple presentation protocols (REST, GraphQL, gRPC) and includes a Postgres persistence layer for account management.

Features

Added Postgres persistence layer for account management

Introduced new Postgres-based implementations for account persistence and retrieval, including the AccountPersisterPostgres and AccountRetrieverPostgres components. The retriever supports filtering by name using a LIKE query and includes pagination support. Helper utilities were added for query construction, safe filter validation, and database readiness checks.

persistence/postgres · high confidence

Initial commit of presentation layer scaffolding

The presentation layer is initialized with a complete set of scaffolding files for REST, GraphQL, gRPC, WebSockets, and telemetry. The REST implementation provides a functional API using the Gin framework, including controllers for account and info endpoints, request parsing for pagination and filters, and a dedicated profiling server for Go pprof metrics. Configuration is structured to support release modes, logging formats, and telemetry settings.

presentation · high confidence

Initial infrastructure layer with configuration, dependency injection, and readiness probes

The \infra\ package introduces the foundational infrastructure layer, including a \Config\ struct for application, REST, logging, and database settings. A \Container\ implements manual dependency injection, wiring up the logger, database adapter, and domain components. Crucially, it registers a readiness checker for the database, enabling health monitoring via the \Readiness\ interface which tracks component states and supports a basic readiness endpoint.

infra · high confidence

Initial release of the Catalyst Go Clean Architecture template

The repository is initialized with a complete, runnable Go microservice template following Clean Architecture principles. This includes the core application entry point (main.go) that handles configuration parsing, dependency injection, and graceful shutdown, alongside a Makefile for build and run workflows, a Dockerfile for containerization, and a new.sh script to scaffold new projects. The template also provides example configuration files, a README with usage instructions, and supporting metadata files.

(repo-wide) · high confidence

Introduce automated build metadata generation

Added a new metadata module that generates build information at runtime. The system now includes a shell script (set\_metadata.sh) that captures repository name, branch, commit hash, release tag, and timestamp into text files. These are embedded into the Go code (read.go) to provide access to Name(), BaseInfo(), and BuildInfo() functions, allowing the application to report its current build status and identity.

metadata · high confidence

Introduces domain-layer interfaces and readiness probes for account management

The domain layer now defines explicit interfaces for account persistence and retrieval, along with a new \Readiness\ interface and \DatabaseTx\ contract to support health checks. Use cases for accounts are implemented with transaction wrapping and readiness state management, allowing the system to detect and report database connectivity issues.

domain · medium confidence

Behavioural changes

Introduce persistence layer contracts and readiness checks

Added new interface contracts for the persistence layer, defining how database adapters interact with the application. The \DatabaseAdapter\ interface standardizes database operations including \Identity\, \Ping\, \Query\, \QueryBulk\, and \Destruct\. Additionally, a \Readiness\ interface is introduced to allow database adapters to report their health status back to the infrastructure, supporting readiness probe checks.

persistence · high confidence

Dependencies

Upgrades Go 1.26 and core dependencies

The project now targets Go 1.26 and updates key dependencies, including gin v1.12.0, the internal catalyst-pkgs package v0.4.0, and the go-playground/validator v10.30.3. Indirect dependencies are also updated, notably golang.org/x/crypto v0.53.0, quic-go v0.60.0, and viper v1.21.0.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 56 → 63 (+6.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-1.1)
  • Architecture 69 → 69 (+0.0)
  • Maturity 64 → 66 (+1.7)
  • Readiness 43 → 53 (+9.7)
  • Security 63 → 78 (+15.9)

Resolved (17)

  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • Medium vulnerability: GO-2026-5932 (go.mod)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • The GRPC section lists a YouTube tutorial link but does not mention how to implement the actual gRPC service or reference the corresponding proto file. (presentation/grpc/README.md)
  • The REST README is very short ('This is only for demonstration'), leaving no guidance on how to run or test the server. (presentation/rest/README.md)

New (24)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium vulnerability: GO-2026-5932 (go.mod)
  • Medium: security finding (details withheld)
  • No ADRs found
  • No dependency advisory monitoring
  • Outdated: github.com/gin-contrib/cors
  • …and 4 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kosatnkn/catalyst was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4ee2ca45a8d15fac79b8d72ddfc663285e177e39 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.