Skip to content
CAI
Software that uses CAICheck a score

mohamedelareeg/CleanArchitecture

50.6

Weak · 21 September 2026

2.9k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a .NET 8 application built on Clean Architecture, structured into distinct layers including API, Application, Domain, and Persistence. It provides core infrastructure for user authentication, role management, and email services, all orchestrated via MediatR. The system manages SQL Server persistence through Entity Framework Core and supports multi-language localization and standardized error handling.

Features

Adds application-layer infrastructure for authentication, email, and role management

Introduces new application features for handling user authentication (login, register, password reset), email sending, and role/claim management, each implemented as MediatR command and query handlers. The change also adds base response and filteration classes, pipeline behaviors for validation and authorization, and a global error-handling middleware that maps exceptions to standardized JSON responses.

(repo-wide) · high confidence

Initial API scaffolding with authentication, role management, and localization

The API project now includes a base controller that standardizes HTTP responses and integrates with MediatR, alongside controllers for authentication (login, register, password reset), email sending, and role/claim management. Swagger is configured with JWT Bearer security and a language header parameter (en-US, ar-EG, de-DE) to support multi-language error messages and UI localization. The application pipeline adds CORS, Serilog, and request localization, while configuration files define database connections, JWT settings, and logging.

CleanArchitecture.Api · medium confidence

Initial database context and repository layer for persistence

The CleanArchitecture.Persistence module now provides the core data access infrastructure. This includes the \ApplicationDbContext\ and \AuditableDbContext\ classes to manage Entity Framework Core state and audit timestamps, a \BaseRepo\<T\>\ generic repository implementing common CRUD and query operations, and the \PersistenceDependencies\ registration to configure the SQL Server connection and dependency injection. Additionally, the initial database migration files have been added to the project.

CleanArchitecture.Persistence · high confidence

Initial project scaffolding and configuration

The repository has been initialized with the core project structure, including the solution file (CleanArchitecture.sln) that defines the .NET 8 Clean Architecture layers (Domain, Application, Infrastructure, Persistence, Identity, API, and MVC). The update also introduces essential development and deployment configurations: a .dockerignore file to exclude unnecessary files from Docker builds, a docker-compose.yml file to orchestrate the API and MVC services, and a launchSettings.json file to enable Docker Compose debugging in Visual Studio. Additionally, the project includes a LICENSE file (MIT) and a comprehensive README.md documenting the architecture and features.

(repo-wide) · high confidence

Dependencies

Added .csproj files for CleanArchitecture solution

Added project configuration files for the CleanArchitecture solution, defining the structure and dependencies for the API, application, domain, identity, infrastructure, MVC, persistence, and test projects. These files establish the .NET 8.0 target framework and include necessary NuGet packages such as Entity Framework Core, MediatR, and various Microsoft libraries.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 51 → 51 (-0.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 63 → 60 (-3.0)
  • Architecture 91 → 91 (+0.0)
  • Maturity 56 → 56 (+0.0)
  • Readiness 36 → 37 (+0.6)
  • Security 69 → 69 (-0.1)
  • Accessibility 80 → 80 (+0.0)

Resolved (33)

  • Bounded contexts not declared
  • Build did not complete in the analyzer
  • Duplicated block (10 lines × 2) (CleanArchitecture.Application/Extenstions/QueryableExtensions.cs)
  • High CVE: System.Text.Json 8.0.0
  • High CVE: System.Text.Json 8.0.0
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent use of 'Add' vs 'Assign' for similar operations. 'AddClaimToRoleCommand' uses 'Add', while 'AssignClaimToUserCommand' uses 'Assign'.
  • Medium CVE: Azure.Identity 1.7.0
  • Medium CVE: Azure.Identity 1.7.0
  • Medium CVE: BouncyCastle.Cryptography 2.2.1
  • Medium CVE: BouncyCastle.Cryptography 2.2.1
  • Medium CVE: BouncyCastle.Cryptography 2.2.1
  • Medium CVE: MimeKit 4.3.0
  • Medium IaC: CKV2_GHA_1 (.github/workflows/dotnetcore.yml)
  • Medium IaC: CKV2_GHA_1 (.github/workflows/main.yml)
  • Medium IaC: CKV_DOCKER_2 (CleanArchitecture.Api/Dockerfile)
  • Medium IaC: CKV_DOCKER_2 (CleanArchitecture.Mvc/Dockerfile)
  • …and 13 more

New (29)

  • CommentedOutCode (CleanArchitecture.Persistence/Repo/BaseRepo.cs)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (12 lines × 2) (CleanArchitecture.Application/Extenstions/QueryableExtensions.cs)
  • Duplicated block (15 lines × 2) (CleanArchitecture.Api/Base/AppControllerBase.cs)
  • High CVE: System.Text.Json 8.0.0
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent naming convention for property suffixes. 'Lastname' uses a camelCase suffix ('name') while other date/status properties like 'CreatedDate' and 'Cancelled' use PascalCase suffixes ('Date', 'Cancelled'). While 'Lastname' is a common compound, in a codebase with 'CreatedDate', 'LastDate' or 'LastName' would be more consistent with the PascalCase style of the other properties.
  • Inconsistent pluralization and spelling of technical terms. 'GetChildsAsync' uses the non-standard plural 'Childs' instead of 'Children'. Additionally, 'FindNoTraking' contains a spelling error ('Traking' instead of 'Tracking') and is inconsistent with the correctly spelled 'GetTableNoTracking' in the same class.
  • Medium CVE: BouncyCastle.Cryptography 2.2.1
  • Medium IaC: WD-DOCKER-0003 (CleanArchitecture.Api/Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (CleanArchitecture.Api/Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (CleanArchitecture.Mvc/Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (CleanArchitecture.Mvc/Dockerfile)
  • Medium: security finding (details withheld)
  • …and 9 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mohamedelareeg/CleanArchitecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0f996e067627653c479d70b5b517c5878787a46b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.