Skip to content
CAI
Software that uses CAICheck a score

lovung/GoCleanArchitecture

60.0

Adequate · 21 September 2026

1.6k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based web service built on Clean Architecture principles, utilizing Google Wire for dependency injection and GORM for database interactions. It provides foundational infrastructure for user management, including transactional registration, secure password hashing, and JWT-based authentication. The application is structured with a modular package layout, automated testing and linting scripts, and deployment configurations for various environments.

Features

Add initial database schema and migration for user table

The application now includes the initial MySQL database setup, including an initialization script to create the 'gocleanarchitecture' database and an 'admin' user. Additionally, database migration files have been added to create the 'users' table (with id, username, and password fields) and its corresponding rollback script.

build, databases · high confidence

Add lint and test automation scripts

Added new shell scripts for the project: 'scripts/lint.sh' runs 'golangci-lint' to check code quality, and 'scripts/test.sh' executes Go tests with coverage reporting and JUnit output. These scripts streamline the development workflow by providing consistent, automated checks for linting and testing.

scripts · high confidence

Added deployment directory structure

Added empty .gitkeep files to create the directory structure for deployment configurations, specifically initializing folders for Heroku, Kubernetes (k8s), and local environments.

deployments · high confidence

Core service CLI and configuration setup

The core service entry point and configuration are now defined, introducing command-line flags for environment, application metadata, HTTP server settings, and MySQL connection parameters. The service initializes the database connection, JWT session, and Gin-based RESTful API, with support for graceful shutdown and logging levels.

cmd · high confidence

Initial project structure and configuration setup

The application now includes a centralized configuration system for managing service settings, including MySQL connection details and server timeouts. The API layer is configured with logging, CORS, and timeout middleware, and exposes health check and root endpoints. Additionally, placeholder directories for various persistence strategies (filesystem, key-value, NoSQL, RDBMS) have been added to the external package.

app/external · high confidence

Introduce core utility packages for data copying, database access, password hashing, JWT handling, logging, and caching

The \pkg\ directory now contains several new utility packages that provide foundational capabilities for the application. The \copier\ package offers a \MustCopy\ function to safely copy data between structures. The \gormer\ package provides a singleton database connection manager for MySQL. Password hashing has been implemented in the \hasher\ package, which includes both a legacy \bcrypt\ implementation and a newer \argon2\-based \password\ module with corresponding tests. The \jwtutil\ package handles JSON Web Token generation, verification, and CSRF token generation. The \logger\ package wraps the \zap\ library to provide a singleton logger with configurable log levels. Finally, the \storage\ package introduces an in-memory cache, and \testhelper\ provides utilities for mocking GORM and testing panics.

pkg · high confidence

Introduce transactional user registration with context-based state management

Added a new user registration flow that manages database transactions via a middleware, ensuring that user creation is either fully committed or rolled back on error. The change introduces a context-based mechanism to pass database connections and transaction states through the request lifecycle, allowing the application to handle errors and success cases consistently across the handler, use case, and repository layers.

app/internal · high confidence

Architecture

Introduce Wire-based dependency injection for application layers

The application's dependency injection is now managed via Google Wire. New registry files define injection sets for singletons, repositories, use cases, handlers, and middleware, with corresponding Wire templates and generated code to assemble the AuthHandler and TransactionMiddleware.

app/registry · high confidence

Dependencies

Initial Go module and dependency setup

The project's Go module file (go.mod) and its corresponding checksum file (go.sum) have been added, establishing the project's dependency graph. This includes the core framework (Gin), ORM (GORM), and various utility libraries, setting the foundation for the application's architecture.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 56 → 60 (+4.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-0.9)
  • Architecture 100 → 94 (-6.0)
  • Maturity 66 → 66 (+0.0)
  • Readiness 46 → 51 (+4.9)
  • Security 72 → 79 (+7.2)
  • Domain Modelling 53 → 59 (+5.6)

Resolved (15)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.sum)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2021-0263 (go.mod)
  • No exposed public API
  • Test reliability not included
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness

New (42)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/jinzhu/copier
  • Dependency pinned to a stale untagged commit: golang.org/x/crypto
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no project overview (README.md)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High secret: WD-SECRET-0002 (.vscode/launch.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.sum)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2021-0263 (go.mod)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 22 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

lovung/GoCleanArchitecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 50d91fd29f9fe8ad550d7d3d9c421a7948f14849 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.