mehdihadeli/go-vertical-slice-template
64.1
Adequate · 21 September 2026
3.6k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based product catalog service that manages product creation and retrieval via a structured HTTP API. It employs the Uber Dig library for dependency injection and utilizes Cobra for its command-line interface. The codebase enforces coding standards through automated linting and formatting, while comprehensive test suites and mock implementations ensure reliability across unit, integration, and end-to-end scenarios.
Features
Add configuration files and Go structs for application settings
The application now includes structured configuration files (config.development.json, config.test.json) and corresponding Go structs (config.go, dependency.go) to manage application options, HTTP server settings, and database connection details. This introduces a new mechanism for loading and binding configuration from environment variables and JSON files, supporting both development and test environments with distinct database names and ports.
config · high confidence
Added build, lint, and test automation scripts
New shell scripts have been added to the scripts directory to automate common development tasks. These include build, format, lint, test, and dependency update scripts, as well as tools for generating mocks, OpenAPI documentation, and installing Go dependencies and tools. This provides a standardized way to run the build, test, and linting workflows.
scripts · high confidence
Introduces Uber's Dig for dependency injection
The application now uses the Uber Dig library for dependency injection, replacing the previous approach. This change introduces a new \Application\ struct that manages a \dig.Container\ to resolve dependencies such as the Echo HTTP server, logger, and configuration. The \ApplicationBuilder\ is updated to populate the container with routes, repositories, and infrastructure services, while the \configureApplication\ function wires up MediatR handlers and Swagger endpoints through the container. This enables more explicit and testable dependency management across the catalog service.
internal/catalogs/shared · high confidence
Introduces structured error handling and dependency injection for the product catalog
The internal package now provides a comprehensive error-handling framework with typed error types (API, application, bad request, conflict, domain, forbidden, and internal server errors) that carry HTTP status codes and messages. These errors are integrated into the Echo web server via a custom error handler and middleware, ensuring consistent JSON:API-style problem details in responses. Additionally, the codebase adopts Uber's 'dig' library for dependency injection, wiring up configuration, database (GORM), and HTTP components, which changes how services are instantiated and accessed throughout the application.
internal · high confidence
Removals
Removed product creation and retrieval handlers
The command handler for creating a product and the query handler for retrieving a product by ID have been deleted from the codebase. This removes the implementation logic for these specific product features.
_internal/products/features/creating\_product, internal/products/features/getting\_product\_by\id · high confidence
Behavioural changes
Added build error log to track build failures
A new file, tmp/build-errors.log, has been added to capture build error output. This file logs 'exit status 1' errors, providing a dedicated location to inspect build failure details.
tmp · low confidence
Enforce commit message linting and pre-commit formatting
The repository now enforces commit message standards and pre-commit code formatting. A new commit-msg hook runs commitlint to validate commit messages, while a pre-commit hook runs the 'make format' command to automatically format code before each commit.
.husky · medium confidence
Migrated dependency injection from sarulabs/di to uber-go/dig
The project's dependency injection implementation has been refactored to use the \uber-go/dig\ library instead of the previous \sarulabs/di\ approach. This change updates the underlying DI framework used for managing application dependencies, which may affect how services are registered and resolved within the application's architecture.
(repo-wide) · high confidence
Refactor application entry point to use Cobra CLI
The application's entry point in cmd/app/main.go has been refactored to use the Cobra CLI framework, replacing the previous manual signal handling and application builder pattern. The main function now executes a Cobra root command that initializes and runs the application, simplifying the startup process and providing a more standard CLI interface for the API.
cmd · high confidence
Test coverage
Added integration, end-to-end, and unit tests for product features; Added mock implementations for testing.
Dependencies
Updated Go dependencies and tooling packages
Updated Go dependencies including \github.com/labstack/echo/v4\ to v4.13.3, \github.com/mehdihadeli/go-mediatr\ to v1.3.0, and \github.com/swaggo/swag\ to v1.16.4. Also updated \@commitlint/cli\ and \@commitlint/config-conventional\ to v19.8.0 and \husky\ to v9.1.7 in the project's \package.json\. Added new dependencies such as \emperror.dev/errors\, \github.com/caarlos0/env/v8\, and \go.uber.org/zap\.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 64 → 64 (-0.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (-0.1)
- Architecture 100 → 83 (-16.9)
- Maturity 75 → 74 (-1.3)
- Readiness 50 → 51 (+1.3)
- Security 78 → 79 (+0.7)
- Domain Modelling 70 → 70 (+0.0)
- Event-Driven 100 → 100 (+0.0)
Resolved (22)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2026-4601 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- Medium vulnerability: GO-2026-5841 (go.mod)
- No exposed public API
- Test reliability not included
- …and 2 more
New (37)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (16 lines × 3) (internal/pkg/http/httperrors/customerrors/api_error.go)
- Duplicated block (16 lines × 9) (internal/pkg/http/httperrors/customerrors/bad_request_error.go)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High IaC: WD-COMPOSE-0002 (deployments/docker-compose/docker-compose.infrastructure.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: internal/pkg/http/httperrors/problemdetails/problem_detail_parser.go (internal/pkg/http/httperrors/problemdetails/problem_detail_parser.go)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2026-4601 (go.mod)
- …and 17 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mehdihadeli/go-vertical-slice-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a57980539fb9d9465895b870ea75fd13129484c2 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.