Skip to content
CAI
Software that uses CAICheck a score

NicklasWallgren/go-template

50.9

Adequate · 21 September 2026

3.5k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based backend service that manages user data and exposes it via a REST API, supported by PostgreSQL or MariaDB and RabbitMQ for messaging. It features a modular architecture with domain-driven event dispatching, structured logging, and comprehensive health checking. The application includes robust testing infrastructure with integration tests and mocks, and is deployed via Kubernetes with observability tracing through DataDog.

Features

Added Postgres support and updated Go tooling

The application now supports PostgreSQL in addition to MariaDB, with new Docker Compose services, environment variable configurations, and migration directories for both databases. The project has been upgraded to Go 1.19, and the linter configuration (.golangci.yml) has been updated to reflect this version and adjust enabled/disabled linters. A new coverage script (coverage.sh) and ignore file (.coverageignore) have been added to streamline test coverage reporting, and the Makefile has been updated to include targets for managing the new Postgres container.

(repo-wide) · high confidence

Initial Kubernetes deployment manifests and Dockerfile update

This change introduces the initial set of Kubernetes manifests for deploying the application infrastructure, including a namespace, an Ingress resource for routing traffic to the backend, and deployments with services and persistent volume claims for MariaDB and RabbitMQ. It also adds Docker initialization scripts for MariaDB and PostgreSQL, and updates the application Dockerfile to use the Go 1.19 base image.

deployment · high confidence

New domain event dispatcher and AMQP integration

The domain/event package now includes a new event dispatcher that manages event listeners and dispatches events via a background consumer goroutine. It introduces an EntityEventListener that bridges domain events to an AMQP publisher, specifically handling User entity events by publishing them to a message queue. This replaces the previous module infrastructure with a dedicated eventing layer.

domain/event · high confidence

Removals

The MySQL database implementation has been removed from the application. This change deletes the \infrastructure/database/mysql.go\ file, which previously handled MySQL connection setup and retry logic using GORM, as well as the \infrastructure/constants/constants.go\ file containing the \DBTransaction\ constant. Users relying on MySQL connectivity will no longer have this driver available in this code path.

infrastructure/database · high confidence

Removal of custom logger infrastructure

The custom logger implementation in the infrastructure layer has been removed. This eliminates the \Logger\ and \GinLogger\ structs, along with their associated methods for integrating with Gin, Go-Fx, and GORM, effectively stripping out the previous logging configuration and adapter logic from the application.

infrastructure/logger · high confidence

Removal of infrastructure module and dependency injection setup

The infrastructure module has been removed, eliminating the centralized dependency injection configuration that previously provided environment variables, logging, database connections, and health checkers via the fx framework. This change removes the \infrastructure\ package and its associated module wiring, meaning these services are no longer automatically registered or available through the previous module structure.

infrastructure · high confidence

Removal of legacy GORM-based persistence repository and criteria model

The generic GORM-based repository implementation and the associated Criteria model have been removed from the persistence adapter. This eliminates the previous database-agnostic data access layer that relied on GORM for operations such as finding, creating, saving, and deleting entities, as well as the Criteria struct used for generating database WHERE clauses. Users relying on this specific generic repository interface for data persistence will need to adopt the new persistence strategy being introduced in this area.

adapters/driver/persistence · high confidence

Removed database health check from infrastructure/health

The database health checker component has been removed from the health infrastructure module. This eliminates the ability to verify database connectivity status as part of the system's health checks, likely due to the concurrent removal of the database module.

infrastructure/health · high confidence

Behavioural changes

API layer restructured with unified error handling and dependency injection

The API adapter module has been reorganized from the 'driven' to the 'driver' package and wired with fx dependency injection. A new priority-based error handling system now standardizes API responses, mapping domain, validation, and API errors to consistent JSON envelopes with appropriate HTTP status codes. The module also introduces a generic response converter for paginated data, a health check endpoint, and an observability middleware integrated with DataDog tracing.

adapters/driver/api · high confidence

Added EntityNotFoundError and refined DomainError constructor

The error handling domain now includes a specific EntityNotFoundError type that captures an entity ID for clearer identification of missing resources. Additionally, the DomainError constructor was refactored to move the function signature above the internal comment, and the Error method now consistently returns the stored message without leaving a TODO placeholder.

domain/errors · high confidence

Added PostgreSQL support and reorganized database resources

The application now supports PostgreSQL as a database backend, introduced via a new migration file for the users table in the postgres directory. To accommodate this, the previous generic migration file has been moved into a dedicated mysql directory, clarifying that it applies specifically to MySQL. Additionally, a new SQL template file (users.tsql) has been added to handle complex queries for the users entity, while the previous Go-based SQL file for this entity has been removed.

resources · high confidence

HTTP server hardening and migration status support

The HTTP server command now enforces a 10-second read header timeout to mitigate slowloris-style attacks and correctly handles graceful shutdown by ignoring the standard http.ErrServerClosed error. Additionally, the migration command has been extended to support a new 'status' flag, allowing users to view the current state of database migrations, and the server command now initializes DataDog APM tracing.

adapters/driver/cmd · high confidence

Refactored application bootstrap and module structure

The application's bootstrap logic has been restructured to align with a new module layout. The \App\ type now uses \cmd.RootCommand\ instead of the previous \cli.RootCommand\, and the configuration assets are typed as \config.AssetsConfig\ rather than \config.Assets\. Internally, the \fx\ options have been updated to import and use \env.Module\ and \driven.Module\ from the \adapters/driven\ package, replacing the old \infra.Module\ and \driver.Module\ references. This change reflects the migration of infrastructure components (CLI, logger, env) into the \adapters\ directory and updates the wiring of these modules in the application startup sequence.

bootstrap · high confidence

Refactored application configuration into dedicated config structs

The application configuration has been restructured to improve modularity and clarity. The previous monolithic \AppConfig\ and related structs in \config/app.go\ have been replaced with specific configuration structs: \AppConfig\, \DatabaseConfig\, \HTTPServerConfig\, \RabbitMQConfig\, and \AssetsConfig\. This change separates concerns by isolating database, HTTP server, RabbitMQ, and asset settings into their own types. Notably, the \AssetsConfig\ now includes a \TemplateSQL\ field alongside \EmbedMigrations\, and the \DatabaseConfig\ explicitly stores the driver/dialect. The \RabbitMQConfig\ retains its \ToDsn\ method for generating connection strings. This refactoring simplifies the configuration structure and prepares the codebase for better dependency injection via FX, as indicated by the cleanup in \module.go\.

config · high confidence

Refactored event dispatcher initialization in domain module

The domain module now initializes the event dispatcher and entity event listener using fx.Provide, replacing the previous direct registration of AMQP event publishers and managers. This change centralizes the event dispatching setup within the domain layer, ensuring the dispatcher is properly configured with the entity event listener before being provided to other components.

domain · high confidence

Removal of driver module dependency injection configuration

The \adapters/driver/module.go\ file has been deleted, removing the centralized fx module configuration that previously wired up RabbitMQ consumers, consumer runners, publishers, and the user repository. This change eliminates the specific dependency injection setup for these driver components from this location.

adapters/driver · high confidence

Restructured infrastructure into driven adapters with new health, logging, and persistence modules

The application's infrastructure layer has been reorganized into the \adapters/driven\ package, introducing dedicated modules for environment configuration, structured logging (Zap), and database persistence (GORM with MySQL/Postgres support). A new health-checking system has been added, featuring a manager that aggregates status from database and RabbitMQ checkers, exposing a unified health status. The persistence layer now includes a generic entity repository, SQL query templating, and specific error handling for database drivers. Additionally, RabbitMQ integration has been implemented with a consumer manager and publisher, while legacy API controllers and converters have been removed from this location.

adapters/driven · high confidence

Standardizes primary identifier naming to PascalCase

The primary identifier type and its associated interface methods in the common domain have been renamed from the camelCase style (PrimaryId, Id) to the PascalCase convention (PrimaryID, ID). This change aligns the codebase with standard Go naming conventions enforced by linters, ensuring consistency across entity definitions and their constraints.

domain/common · high confidence

User service refactoring: criteria-based queries, context propagation, and event dispatching

The user domain now supports filtering and paginating users via new criteria-based methods (FindAllUsersByCriteria and Overview) in addition to the existing list endpoint. The user service has replaced the generic event publisher with a dedicated event dispatcher, emitting entity events upon creation. Validation logic across the domain now accepts a context.Context parameter, allowing validators to use context-aware operations (such as passing the context to repository lookups for unique email checks). Additionally, the service now returns a specific 'not found' error when a user ID does not exist, and the user entity's JSON tags for timestamps have been updated.

domain/users · high confidence

Test coverage

Added generated mocks for domain event interfaces; Added integration tests for health and user APIs with updated test utilities; Added mock for UserService to support testing; Expanded integration tests for user persistence repository; Regenerated UserRepository mock to use new expecter interfaces; Regenerated test mocks for driven and driver adapters; Regenerated test mocks to use new expecter interfaces; Updated integration test infrastructure and imports; Updated test infrastructure to support modular dependency injection and multi-database configurations; Updated user factory test helper to use new persistence package path.

Dependencies

Updated Go version and upgraded core dependencies

The project now targets Go 1.19 and upgrades the Gin web framework to v1.8.1. New dependencies have been added to support PostgreSQL via GORM and the Jackc driver, enable DataDog observability tracing, and integrate RabbitMQ messaging. Several other libraries, including Swagger tools and test assertions, have also been updated to their latest versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 47 → 51 (+4.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 89 (-10.9)
  • Architecture 100 → 71 (-29.2)
  • Maturity 55 → 55 (+0.0)
  • Readiness 60 → 53 (-6.8)
  • Security 61 → 56 (-4.3)
  • Domain Modelling 27 → 43 (+15.3)
  • Event-Driven 89 → 89 (+0.0)

Resolved (17)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (adapters/driven/persistence/entity_repository.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • single-maintainer — knowledge-concentration (bus factor) risk

New (179)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/rs/cors/wrapper/gin
  • Dependency pinned to a stale untagged commit: github.com/swaggo/files
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (adapters/driven/persistence/entity_repository.go)
  • Duplicated block (8 lines × 2) (adapters/driven/persistence/entity_repository.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High IaC: WD-DOCKER-0013 (deployment/docker/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 159 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

NicklasWallgren/go-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d389d3b8415ef18434f334641af80dd54118b353 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.