Skip to content
CAI
Software that uses CAICheck a score

OFFLINE-GmbH/go-webapp-example

49.3

Weak · 21 September 2026

5.2k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Behavioural changes

Removal of Sentry error tracking

The application no longer reports errors to Sentry. Error handling for database migrations and application shutdown has been simplified to log messages directly, removing the previous behavior of capturing exceptions in Sentry.

cmd · high confidence

Removed Sentry error tracking integration

The application no longer reports errors to Sentry. All calls to the Sentry SDK have been removed from the HTTP server startup, backup daemon, and GraphQL error handlers, and the Sentry import has been deleted from the codebase.

internal · high confidence

Updated README with new feature list and configuration instructions

The README.md has been updated to list new features including a GraphQL server, user sessions, role-based access control, one-time update routines, i18n, background processes, and tests. The documentation also now includes a section on changing the application configuration via config.toml, and clarifies that the serve command starts the backend server without live reloading. Additionally, the magefile.go was modified to return 'no-repo' for version generation when git is unavailable, and the frontend build process was stubbed out.

(repo-wide) · medium confidence

Dependencies

Removed Sentry and StatsD dependencies

The Go module manifest (go.mod) and its checksum file (go.sum) were updated to remove several unused or obsolete dependencies. Specifically, the entry for 'github.com/getsentry/sentry-go' was removed, aligning with the removal of Sentry calls. Additionally, dependencies for 'github.com/statsd/client' and 'github.com/statsd/client-interface' were removed, likely due to the removal of StatsD integration. The diff also shows 'github.com/google/go-cmp' being marked as an indirect dependency, and new test dependencies 'github.com/onsi/ginkgo' and 'github.com/onsi/gomega' were added.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 54 → 49 (-4.6)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 98 (+1.3)
  • Architecture 100 → 99 (-1.4)
  • Maturity 62 → 66 (+3.9)
  • Readiness 27 → 21 (-6.1)
  • Security 90 → 71 (-19.1)

Resolved (19)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (internal/pkg/quote/store.go)
  • Duplicated block (10 lines × 2) (internal/pkg/role/store.go)
  • Duplicated block (11 lines × 2) (internal/graphql/gqlresolvers/role.go)
  • Duplicated block (12 lines × 2) (internal/graphql/gqlresolvers/user.go)
  • Duplicated block (6 lines × 2) (internal/graphql/gqldataloaders/middleware.go)
  • Duplicated block (8 lines × 2) (internal/pkg/role/store.go)
  • Duplicated block (8 lines × 2) (internal/pkg/role/store.go)
  • Duplicated block (9 lines × 2) (internal/pkg/quote/store.go)
  • Duplicated block (9 lines × 3) (internal/pkg/quote/store.go)
  • Low IaC: DS-0005 (build/docker/Dockerfile)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • complexity unreadable for .go — churn × complexity hotspots could not be measured
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • single-maintainer — knowledge-concentration (bus factor) risk

New (71)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/alexedwards/scs/mysqlstore
  • Dependency pinned to a stale untagged commit: github.com/mgutz/ansi
  • Dependency pinned to a stale untagged commit: golang.org/x/crypto
  • Deprecated module: github.com/go-chi/chi
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (11 lines × 2) (internal/graphql/gqlresolvers/user.go)
  • Duplicated block (11–12 lines × 2) (internal/pkg/quote/store.go)
  • Duplicated block (14–15 lines × 2) (internal/pkg/quote/store.go)
  • Duplicated block (5 lines × 2) (internal/pkg/role/store.go)
  • Duplicated block (7 lines × 2) (internal/pkg/audit/store.go)
  • Duplicated block (7 lines × 2) (internal/pkg/quote/store.go)
  • Duplicated block (7 lines × 2) (internal/pkg/role/store.go)
  • Duplicated block (7 lines × 2) (internal/pkg/role/store.go)
  • Duplicated block (7 lines × 2) (internal/pkg/role/store.go)
  • Duplicated block (7 lines × 3) (internal/pkg/quote/store.go)
  • Duplicated block (8 lines × 2) (internal/pkg/role/store.go)
  • Duplicated block (8 lines × 2) (internal/pkg/user/validation.go)
  • Duplicated block (9 lines × 2) (internal/graphql/gqlresolvers/role.go)
  • …and 51 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

OFFLINE-GmbH/go-webapp-example was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a0b09ae6143c384956802d5a2cf5037954f9e373 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.