nurcahyaari/golang-starter
52.6
Adequate · 20 September 2026
3.3k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based backend service implementing a clean architecture for managing users and products. It provides secure authentication via JWT, handles data persistence through MySQL with Redis caching, and exposes a REST API using the Chi router. The application supports transactional data integrity, graceful shutdowns, and standardized logging and response formatting.
How it got here
2020–2021 — Initial project scaffolding and infrastructure setup
10 changes.
This period established the foundational structure of the Go application, implementing clean architecture, Docker support, and JWT authentication. It involved configuring centralized YAML settings, integrating Chi for HTTP routing, and setting up native SQL with Redis caching. The work also included standardizing HTTP responses, logging, and API documentation to create a robust development baseline.
2022 — Core module and infrastructure scaffolding
6 changes.
This period focused on establishing the foundational architecture for the application, including the creation of the product and user modules with their respective repository layers and DTOs. It involved implementing core infrastructure components such as database transaction management, local database support, and graceful shutdown capabilities to ensure robust service handling.
Features
Add database transaction management layer
A new transaction layer has been introduced in the database infrastructure to manage database transactions. This component provides methods to start, commit, and rollback transactions, as well as a helper function to execute a given operation within a transactional context, automatically handling rollback on failure and commit on success.
infrastructures/db/transaction · high confidence
Add local database implementation using Scribble
The localdb infrastructure now includes a new implementation (scribble.go) that initializes a Scribble driver backed by a local 'tmp/db' directory. This provides a concrete local database client for use within the application's infrastructure layer.
infrastructures/localdb · high confidence
Added MySQL database schema for products, users, and images
A new migration file for MySQL has been added to initialize the database schema. This includes the creation of \products\, \users\, and \products\_images\ tables, along with their respective primary keys, foreign key constraints, and initial seed data for testing purposes.
migrations · high confidence
Graceful shutdown support for application services
The application now supports graceful shutdown, allowing registered operations to complete before the process exits. When an interrupt signal (SIGINT or SIGTERM) is received, the system waits for all registered operations to finish, up to a specified timeout, after which it forces an exit if necessary.
internal/graceful · high confidence
Initial release of Golang boilerplate with clean architecture, Docker support, and JWT authentication
This entry introduces the initial project structure, establishing a clean architecture layout with separate folders for configuration, infrastructure, internal utilities, and domain modules (user, product). It adds Docker support via a multi-stage Dockerfile and docker-compose.yml (including MySQL and phpMyAdmin services), implements graceful shutdown handling for the HTTP server, and integrates JWT authentication with RSA key support. The project also includes a Makefile for build and development workflows, Wire for dependency injection, and example configuration files (.env.example, config.yaml.example) to guide setup.
(repo-wide) · high confidence
Introduction of Zerolog-based logging and RabbitMQ handler structure
The application now includes a dedicated logging module that initializes Zerolog with Unix time fields and RFC3339 console output, ensuring consistent and readable log formatting. Additionally, the foundational structure for the RabbitMQ message handler has been added, establishing the package context for future message processing logic.
internal/logger, src/handlers/rabbitmq · medium confidence
Introduction of standardized HTTP response helpers and JWT middleware
This change introduces new internal packages for handling HTTP responses and authentication. The \internal/protocols/http/response\ package provides utility functions (\Json\, \Text\, \Err\) to standardize how API responses are formatted and written, ensuring consistent JSON structures and error handling. Additionally, the \internal/protocols/http/middleware\ package adds JWT verification middleware (\JwtVerifyToken\ and \JwtVerifyRefreshToken\) that validates access and refresh tokens using RSA public keys, extracting user IDs and setting them in the request context for downstream handlers.
internal/protocols/http/response · high confidence
New internal utility packages for authentication, encryption, and SQL helpers
This change introduces a new \internal/utils\ structure containing several reusable components. The \auth\ package provides JWT token generation (supporting both HS256 and RS256 signing methods) and defines DTOs for access and refresh tokens, with refresh tokens being encrypted via AES-CFB and stored in a local database cache. The \encryption\ package exposes AES-CFB encryption and decryption utilities, including key length normalization. Additionally, the \sqlhelper\ package adds convenience functions for safely handling \sql.NullString\, \sql.NullFloat64\, \sql.NullInt32\, and \sql.NullInt64\ types, with corresponding unit tests verifying their behavior.
internal/utils · high confidence
Product module scaffolding with transactional creation support
The product module now includes generated repository layers for the \products\ and \products\_images\ tables, along with DTOs for request/response mapping. The \ProductService\ implements a \CreateNewProduct\ workflow that uses a transaction layer to ensure the product and its associated images are inserted atomically, preventing partial data states if the image insertion fails after the product is created.
src/modules/product · high confidence
User module introduces login, token refresh, and repository layer
The user module now provides a complete authentication flow, including user login and JWT token refresh capabilities. This change adds DTOs for login requests and token responses, entity definitions for users and refresh tokens, and a repository layer that handles user data persistence via SQL and refresh token storage in a local database. The service layer implements login verification using bcrypt, JWT signing, and token validation logic, enabling users to authenticate and maintain sessions.
src/modules/user · high confidence
Behavioural changes
HTTP server implementation switched to Chi router with graceful shutdown support
The internal HTTP protocol implementation now uses the Chi router (github.com/go-chi/chi/v5) instead of the previous framework, and exposes a Shutdown method that performs a graceful server shutdown via context. Users benefit from the Chi routing behavior and reliable shutdown handling when the application terminates.
internal/protocols/http · high confidence
Introduction of centralized YAML-based configuration management
The application now uses a new \config\ package to manage settings via a YAML file (loaded by Viper) instead of the previous \.env\ approach. This change introduces structured configuration for the application server (port, logging, graceful shutdown duration), authentication (JWT token types and expiration), database (MySQL connection details), and caching (Redis connection details), making these settings explicitly defined and centrally accessible.
config · high confidence
Migrate HTTP handlers to the Chi router
The HTTP handler layer has been rewritten to use the Chi router instead of the previous framework. This change updates the routing configuration and handler implementations for product and user endpoints (including login and token refresh), ensuring compatibility with the new router while maintaining the same API surface.
src/handlers/http · high confidence
Migrate HTTP router to Chi and add Swagger documentation
The HTTP router implementation has been switched from the previous framework to Chi (github.com/go-chi/chi/v5), introducing a new routing structure in the router package. This change includes the addition of automatic Swagger documentation, which is now accessible at the /swagger endpoint via the http-swagger handler, and configures CORS to allow all origins by default.
internal/protocols/http/router · high confidence
Replace ORM with native SQL and add Redis caching infrastructure
The database layer has been refactored to remove the previous ORM in favor of native queries generated by the sqlabst library, while a new Redis caching implementation has been added to provide both direct client access and a local-cache-backed cache layer for improved performance.
infrastructures/db · high confidence
Dependencies
Initial Go module setup with Chi, Redis, and JWT dependencies
The project initializes its Go module (golang-starter) with a specific set of dependencies, establishing the foundational libraries for the application. This includes the Chi v5 HTTP router (replacing the previously mentioned Fiber framework), the golang-jwt library for authentication, and go-redis for caching and data storage. Additional tooling includes Wire for dependency injection, Swag for API documentation, and Air for development hot-reloading.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 56 → 53 (-3.2)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 98 → 97 (-0.9)
- Architecture 100 → 66 (-34.3)
- Maturity 73 → 73 (+0.0)
- Readiness 26 → 29 (+3.4)
- Security 81 → 75 (-5.1)
- Domain Modelling 100 → 100 (+0.0)
Resolved (14)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (10 lines × 3) (src/modules/product/repositories/products_images_repo_query_gen.go)
- Duplicated block (10 lines × 3) (src/modules/product/repositories/products_images_repo_query_gen.go)
- Duplicated block (12 lines × 2) (internal/protocols/http/middleware/jwt.go)
- Duplicated block (13 lines × 5) (src/modules/product/repositories/products_images_repo_query_gen.go)
- Duplicated block (13 lines × 8) (src/modules/user/repositories/users_repo_query_gen.go)
- Duplicated block (13 lines × 9) (src/modules/product/repositories/products_repo_query_gen.go)
- Duplicated block (14 lines × 2) (internal/utils/auth/jwt.go)
- Duplicated block (17–18 lines × 2) (internal/utils/auth/jwt.go)
- Medium: security finding (details withheld)
- No exposed public API
- Test reliability not included
- dormant codebase — no living knowledge left to concentrate
New (58)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: github.com/nanobox-io/golang-scribble
- Dependency pinned to a stale untagged commit: github.com/nurcahyaari/sqlabst
- Dependency pinned to a stale untagged commit: golang.org/x/crypto
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (internal/protocols/http/middleware/jwt.go)
- Duplicated block (12 lines × 2) (src/modules/product/repositories/products_images_repo_query_gen.go)
- Duplicated block (12 lines × 2) (src/modules/product/repositories/products_images_repo_query_gen.go)
- Duplicated block (12 lines × 2) (src/modules/product/repositories/products_repo_query_gen.go)
- Duplicated block (12–13 lines × 2) (internal/protocols/http/middleware/jwt.go)
- Duplicated block (13 lines × 3) (src/modules/product/repositories/products_images_repo_command_gen.go)
- Duplicated block (14 lines × 5) (src/modules/product/repositories/products_images_repo_query_gen.go)
- Duplicated block (14 lines × 8) (src/modules/user/repositories/users_repo_query_gen.go)
- Duplicated block (14 lines × 9) (src/modules/product/repositories/products_repo_query_gen.go)
- Duplicated block (15–16 lines × 2) (internal/utils/auth/jwt.go)
- Duplicated block (20 lines × 2) (internal/utils/auth/jwt.go)
- Duplicated block (24 lines × 3) (src/modules/product/repositories/products_images_repo_query_gen.go)
- Duplicated block (5 lines × 2) (internal/protocols/http/middleware/jwt.go)
- …and 38 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nurcahyaari/golang-starter was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4ca15abd4a464bd979549b91219fd57a6d56d698 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.