ocw-central/ocw-central-backend
58.9
Weak · 21 September 2026
2.5k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based backend service that exposes a GraphQL API for querying academic content, including subjects, videos, and syllabi. It manages a MySQL database schema and provides persistence, domain logic, and data access layers for these entities. The architecture supports environment-specific configurations and includes utilities for database migrations and mock data generation.
Features
Add environment configuration loader for application settings
A new \env\ package has been introduced to centralize the loading of environment variables for the application. This includes configuration for the server port, MySQL database credentials (user, password, address, and database name), and the application environment. The \NewEnvConfig\ function automatically reads these values from the environment using the \envconfig\ library, making it easier to manage application settings across different environments.
env · high confidence
Add interactor layer for academic fields, resources, subjects, syllabi, and videos
The application introduces a new interactor layer that implements business logic for retrieving academic fields, resources, subjects, syllabi, and videos. This includes fetching subjects by ID, by search parameters (title, faculty, academic field), and randomly with caching, as well as retrieving videos and their associated subjects. Each interactor delegates to its respective repository, ensuring a clean separation of concerns and providing a consistent interface for data access.
interactor · high confidence
Added Dockerfile and deployment script for the server container
The docker/server directory now includes a Dockerfile that builds the Go application using a multi-stage build, installs the golang-migrate binary and the ufoscout/docker-compose-wait utility, and sets the container's entrypoint to run deploy.sh. The deploy.sh script waits for dependencies to be ready before executing the main binary, ensuring the server starts only after the database is available.
docker/server · high confidence
Added Dockerfiles and configuration for MySQL and database migration
Introduced new Docker build files and scripts to support database migrations and MySQL containerization. The migration process is now containerized via a new \docker/migrate\ directory containing a \Dockerfile\ and a \migrate.sh\ script that handles environment-specific migration logic (LOCAL, DEV, PROD). Additionally, a new \docker/mysql\ directory provides a \Dockerfile\ and \my.cnf\ configuration to set up a MySQL 8.0.30 container with UTF-8mb4 character set and specific performance settings.
docker/migrate · high confidence
Added script to generate mock data for development
A new script directory \script/create\_mock\_data\ was added, containing a Python script (\create\_mock.py\) and an SQL file (\create\_mock.sql\) that populate a local database with sample data. The Python script uses a breadth-first search to identify a closed set of related subjects, which are then used by the SQL file to insert mock records into tables such as \subjects\, \videos\, \chapters\, \translations\, \resources\, \syllabuses\, and \subpages\. A \.gitignore\ file was also added to the directory to exclude common Python and build artifacts.
script · high confidence
Added utility functions for nil handling and error ignoring
Added new utility functions in the utils package: a generic ConvertNilToZeroValue function that safely converts a pointer to its zero value when nil, and an IgnoreErr function to discard error values.
utils · high confidence
Initial GraphQL schema and resolvers for subjects, videos, and related entities
The graph area now includes a complete GraphQL API for managing and querying academic subjects, videos, and related resources. The schema defines types for Subject, Video, Syllabus, AcademicField, and Translations, along with queries to retrieve subjects by title, faculty, or academic field, fetch random subjects, and search for subjects with specified videos. Resolvers are implemented to fetch data from underlying use cases, and model structs are generated to map between the GraphQL layer and the domain objects.
graph · high confidence
Initial database schema and migration scripts added
The application now includes the foundational database schema, establishing tables for subjects, videos, syllabuses, chapters, resources, subpages, and subject relationships. A subsequent migration adds a transcription field to the videos table, and a third migration introduces a translations table to support multilingual content. These changes enable the storage and retrieval of core educational data, video metadata, and associated translations.
migrations · high confidence
Initial project scaffolding and configuration
The repository is initialized with essential configuration and infrastructure files. This includes a Docker Compose setup for the server, database, and migrations, alongside a \.env.template\ for environment variables. The Go backend is configured with \gqlgen\ for GraphQL code generation and \wire\ for dependency injection. Additionally, a \server.go\ entry point is added, which configures CORS headers for local, dev, and production origins, exposes a \/health\ endpoint, and conditionally enables the GraphQL playground. The project also includes a \LICENSE.md\ (MIT), a \.dockerignore\, and a \README.md\ with setup instructions.
(repo-wide) · high confidence
Introduce domain models for video, chapter, subject, and syllabus
The model package now includes new domain models for Video, Chapter, Resource, Subject, Subpage, Syllabus, and Translation, each with corresponding accessor files. Each model defines a struct with fields such as title, ordering, transcription, and academic fields, along with a typed ID wrapper (ULID) and a constructor function. This adds the core data structures for video content, course syllabi, and related entities.
model · high confidence
Introduce persistence layer for video, subject, and syllabus data
Added a new persistence package containing repository implementations for videos, subjects, syllabuses, and academic fields, along with corresponding DTOs and database connection logic. This provides the data access layer for retrieving and storing course-related information.
persistence · high confidence
Introduces domain repository and use-case interfaces for academic subjects, videos, and syllabi
The domain layer now defines repository interfaces for AcademicField, Resource, Subject, Syllabus, and Video, each exposing methods to fetch entities by ID, by search parameters, or by random selection. Corresponding use-case interfaces are added for each entity, enabling the application layer to retrieve and transform data into DTOs (Chapter, Resource, Subject, Syllabus, Translation, Video, etc.). This establishes the backend structure for querying and presenting course-related information.
domain · high confidence
Dependencies
Added Go build tools for code generation and dependency injection
A new 'tools' package was introduced to manage development dependencies, specifically importing the gqlgen library for GraphQL code generation and the Google Wire library for dependency injection scaffolding.
tools · high confidence
Initial Go and Python dependency manifests added
The project now includes a Go module definition (go.mod) and its corresponding checksum file (go.sum), establishing the Go 1.19 environment and specifying direct dependencies such as gqlgen, the MySQL driver, Wire, sqlx, and gqlparser, along with their indirect dependencies. Additionally, a requirements file for a Python script was added, specifying mysql-connector-python as a dependency.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 52 → 59 (+6.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 98 (-1.5)
- Architecture 100 → 85 (-14.7)
- Maturity 32 → 45 (+12.3)
- Readiness 47 → 50 (+3.6)
- Security 80 → 90 (+10.0)
- Domain Modelling 100 → 100 (+0.0)
Resolved (16)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (9 lines × 2) (persistence/subject_repository_impl.go)
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2023-2041 (go.mod)
- Medium IaC: CKV_DOCKER_3 (docker/mysql/Dockerfile)
- Medium IaC: CKV_DOCKER_3 (docker/server/Dockerfile)
- Medium IaC: CKV_DOCKER_7 (docker/migrate/Dockerfile)
- No exposed public API
- The How to start this app section is a single bulleted list with only one actionable step (import data) and no links, while the mock_data.md reference is an external link. (README.md)
- complexity unreadable for .go, .py — churn × complexity hotspots could not be measured
- dormant codebase — no living knowledge left to concentrate
New (39)
- Documentation: no architecture or design documentation (README.md)
- Duplicated block (10 lines × 2) (interactor/subject_interactor.go)
- Duplicated block (10 lines × 2) (persistence/subject_repository_impl.go)
- Duplicated block (20 lines × 4) (persistence/resource_repository_impl.go)
- Duplicated block (8 lines × 2) (persistence/subject_repository_impl.go)
- Duplicated block (9 lines × 2) (graph/query.resolvers.go)
- Duplicated block (9 lines × 2) (graph/scalar/int16.go)
- FixmeComment (persistence/subject_repository_impl.go)
- FixmeComment (persistence/subject_repository_impl.go)
- High CVE: [GHSA redacted] (go.mod)
- High IaC: WD-DOCKER-0001 (docker/migrate/Dockerfile)
- High IaC: WD-DOCKER-0001 (docker/server/Dockerfile)
- High IaC: WD-DOCKER-0013 (docker/server/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low IaC: DS-0026 (docker/server/Dockerfile)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2023-2041 (go.mod)
- …and 19 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ocw-central/ocw-central-backend was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 5f5a93ce96059cbab660d33b410846448044ddde — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.