kosatnkn/catalyst
62.8
Weak · 21 September 2026
1.1k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based microservice template implementing Clean Architecture, designed to scaffold and manage account-related domain logic. It provides a complete infrastructure layer with dependency injection, automated build metadata, and database readiness probes. The architecture supports multiple presentation protocols (REST, GraphQL, gRPC) and includes a Postgres persistence layer for account management.
Features
Added Postgres persistence layer for account management
Introduced new Postgres-based implementations for account persistence and retrieval, including the AccountPersisterPostgres and AccountRetrieverPostgres components. The retriever supports filtering by name using a LIKE query and includes pagination support. Helper utilities were added for query construction, safe filter validation, and database readiness checks.
persistence/postgres · high confidence
Initial commit of presentation layer scaffolding
The presentation layer is initialized with a complete set of scaffolding files for REST, GraphQL, gRPC, WebSockets, and telemetry. The REST implementation provides a functional API using the Gin framework, including controllers for account and info endpoints, request parsing for pagination and filters, and a dedicated profiling server for Go pprof metrics. Configuration is structured to support release modes, logging formats, and telemetry settings.
presentation · high confidence
Initial infrastructure layer with configuration, dependency injection, and readiness probes
The \infra\ package introduces the foundational infrastructure layer, including a \Config\ struct for application, REST, logging, and database settings. A \Container\ implements manual dependency injection, wiring up the logger, database adapter, and domain components. Crucially, it registers a readiness checker for the database, enabling health monitoring via the \Readiness\ interface which tracks component states and supports a basic readiness endpoint.
infra · high confidence
Initial release of the Catalyst Go Clean Architecture template
The repository is initialized with a complete, runnable Go microservice template following Clean Architecture principles. This includes the core application entry point (main.go) that handles configuration parsing, dependency injection, and graceful shutdown, alongside a Makefile for build and run workflows, a Dockerfile for containerization, and a new.sh script to scaffold new projects. The template also provides example configuration files, a README with usage instructions, and supporting metadata files.
(repo-wide) · high confidence
Introduce automated build metadata generation
Added a new metadata module that generates build information at runtime. The system now includes a shell script (set\_metadata.sh) that captures repository name, branch, commit hash, release tag, and timestamp into text files. These are embedded into the Go code (read.go) to provide access to Name(), BaseInfo(), and BuildInfo() functions, allowing the application to report its current build status and identity.
metadata · high confidence
Introduces domain-layer interfaces and readiness probes for account management
The domain layer now defines explicit interfaces for account persistence and retrieval, along with a new \Readiness\ interface and \DatabaseTx\ contract to support health checks. Use cases for accounts are implemented with transaction wrapping and readiness state management, allowing the system to detect and report database connectivity issues.
domain · medium confidence
Behavioural changes
Introduce persistence layer contracts and readiness checks
Added new interface contracts for the persistence layer, defining how database adapters interact with the application. The \DatabaseAdapter\ interface standardizes database operations including \Identity\, \Ping\, \Query\, \QueryBulk\, and \Destruct\. Additionally, a \Readiness\ interface is introduced to allow database adapters to report their health status back to the infrastructure, supporting readiness probe checks.
persistence · high confidence
Dependencies
Upgrades Go 1.26 and core dependencies
The project now targets Go 1.26 and updates key dependencies, including gin v1.12.0, the internal catalyst-pkgs package v0.4.0, and the go-playground/validator v10.30.3. Indirect dependencies are also updated, notably golang.org/x/crypto v0.53.0, quic-go v0.60.0, and viper v1.21.0.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 56 → 63 (+6.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 99 (-1.1)
- Architecture 69 → 69 (+0.0)
- Maturity 64 → 66 (+1.7)
- Readiness 43 → 53 (+9.7)
- Security 63 → 78 (+15.9)
Resolved (17)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2026-5970 (go.mod)
- Medium IaC: CKV_DOCKER_3 (Dockerfile)
- Medium vulnerability: GO-2026-5932 (go.mod)
- No exposed public API
- Off-boarding risk: anonymized user #1
- The GRPC section lists a YouTube tutorial link but does not mention how to implement the actual gRPC service or reference the corresponding proto file. (presentation/grpc/README.md)
- The REST README is very short ('This is only for demonstration'), leaving no guidance on how to run or test the server. (presentation/rest/README.md)
New (24)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2026-5970 (go.mod)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium vulnerability: GO-2026-5932 (go.mod)
- Medium: security finding (details withheld)
- No ADRs found
- No dependency advisory monitoring
- Outdated: github.com/gin-contrib/cors
- …and 4 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
kosatnkn/catalyst was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4ee2ca45a8d15fac79b8d72ddfc663285e177e39 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.