Skip to content
CAI
Software that uses CAICheck a score

phamtai97/go-experienced-series

52.4

Adequate · 21 September 2026

664

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Go-based user service built on a hexagonal architecture, exposing functionality via gRPC and HTTP interfaces. It manages user sign-up logic and persists data using MySQL, supported by a structured dependency stack including the Gin framework and Zap logger.

Features

Initial release of the hexagonal architecture Go service

The hexagonal directory now contains a complete Go application implementing a hexagonal architecture. This includes gRPC and HTTP server runners, controllers for both protocols, a user service with sign-up logic, and repository implementations for MySQL. The project also includes a gRPC API definition (user\_service.proto) with generated Go code, along with Buf tooling for API management. A shutdown hook is added to the gRPC runner to ensure graceful resource cleanup.

hexagonal · high confidence

Dependencies

Added Go module dependencies for the user-service

The hexagonal directory now includes a go.mod file and its corresponding go.sum lockfile, establishing the Go 1.19 module 'user-service'. This introduces key dependencies including the Gin web framework (v1.9.1), the Go SQL driver for MySQL (v1.7.1), the Zap logger (v1.18.1), and gRPC/protobuf libraries (v1.59.0 and v1.31.0), along with their indirect dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 50 → 52 (+2.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.2)
  • Architecture 69 → 69 (+0.0)
  • Maturity 57 → 52 (-5.5)
  • Readiness 26 → 38 (+12.2)
  • Security 91 → 72 (-19.3)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (17)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (hexagonal/go.mod)
  • Critical CVE: [GHSA redacted] (hexagonal/go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (19 lines × 2) (hexagonal/cmd/grpc/runner.go)
  • Medium CVE: [GHSA redacted] (hexagonal/go.mod)
  • Medium CVE: [GHSA redacted] (hexagonal/go.mod)
  • Medium CVE: GO-2023-2041 (hexagonal/go.mod)
  • Medium CVE: GO-2026-5024 (hexagonal/go.mod)
  • Medium CVE: GO-2026-5970 (hexagonal/go.mod)
  • No exposed public API
  • Test reliability not included
  • The README lists only one visible heading ('## 1. Hexagonal architecture') with no project-level documentation. (README.md)
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient
  • single-maintainer — knowledge-concentration (bus factor) risk

New (15)

  • Critical CVE: [GHSA redacted] (hexagonal/go.mod)
  • Critical CVE: [GHSA redacted] (hexagonal/go.mod)
  • Duplicated block (18 lines × 2) (hexagonal/cmd/grpc/runner.go)
  • Medium CVE: [GHSA redacted] (hexagonal/go.mod)
  • Medium CVE: [GHSA redacted] (hexagonal/go.mod)
  • Medium CVE: GO-2023-2041 (hexagonal/go.mod)
  • Medium CVE: GO-2026-5024 (hexagonal/go.mod)
  • Medium CVE: GO-2026-5970 (hexagonal/go.mod)
  • Medium: security finding (details withheld)
  • No ADRs found
  • Outdated: github.com/gin-gonic/gin
  • Outdated: github.com/go-sql-driver/mysql
  • Outdated: go.uber.org/zap
  • Outdated: google.golang.org/grpc
  • Outdated: google.golang.org/protobuf

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

phamtai97/go-experienced-series was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f0fb7928ecf39b611743207a314ab65c350c18ec — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.