Skip to content
CAI
Software that uses CAICheck a score

pvarentsov/go-backend-template

50.6

Adequate · 21 September 2026

1.3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add environment-based configuration for HTTP, database, and auth

The application now supports configuration via environment variables and an optional .env file. Users can set HTTP\_HOST, HTTP\_PORT, HTTP\_DETAILED\_ERROR, DATABASE\_URL, ACCESS\_TOKEN\_EXPIRES\_TTL, and ACCESS\_TOKEN\_SECRET to control server binding, error verbosity, database connectivity, and authentication token settings. A .env.template file is provided as a reference for required environment variables.

config · high confidence

Introduce HTTP API layer with user and authentication endpoints

Added a new HTTP server and router in the api/http package to expose user and authentication endpoints. The server initializes a Gin-based HTTP engine and registers routes for login, user management (add, update, change password, get current user), and a login endpoint. The router includes middleware for tracing, logging, and recovery. Authentication is handled via a token-based middleware that sets user ID in the request context. Error handling is standardized with a parseError function that maps internal errors to HTTP status codes.

api/http · high confidence

Introduce HTTP server entry point with dependency injection

Added a new \cmd/http/main.go\ file that serves as the application's HTTP entry point. This file wires together the database client, crypto service, user repository, auth service, and user use cases to initialize and start the HTTP server. This change provides a concrete implementation for the HTTP server, utilizing environment variable configuration and a structured dependency injection approach.

cmd · high confidence

Introduce internal authentication service with login and token verification

Added the internal authentication service implementation, including the \AuthService\ interface and its concrete \authService\ struct in \internal/auth/impl/service.go\, which provides \Login\, \VerifyAccessToken\, and \ParseAccessToken\ methods. The change also introduces data transfer objects (\LoginUserDto\, \LoggedUserDto\) in \internal/auth/dto.go\ and corresponding mock implementations for testing in \internal/auth/mock/\. This establishes the core logic for user login, JWT token generation, and access token validation within the application's internal architecture.

internal/auth · high confidence

Introduce user management capabilities

Added the internal/user package to support user management, including data transfer objects (UserDto, AddUserDto, UpdateUserDto, ChangeUserPasswordDto), a UserModel with validation and password hashing, a UserRepository interface and PostgreSQL implementation for CRUD operations, and a UserUsecases interface with implementations for adding, updating, and changing passwords. The change also includes generated mocks for testing and unit tests for the use cases.

internal/user · high confidence

Introduces base infrastructure for cryptography, database access, error handling, and request context

Added new internal/base packages providing foundational utilities: a crypto package with a Crypto interface and implementation for password hashing, JWT generation/validation, and UUID generation; a database package defining interfaces and implementations for PostgreSQL connection management and transaction handling; a standardized error handling system with typed status codes and wrapping; and a request context helper to propagate user and trace identifiers through the request lifecycle.

internal/base · high confidence

Introduction of CLI configuration parsing via Kong

A new CLI module has been added to parse environment configuration. It utilizes the Kong library to handle command-line argument parsing and delegates to the config package to read environment variables or configuration files, enabling users to specify an optional path to an env config file.

api/cli · high confidence

Behavioural changes

Added initial database migration for the users table

A new database migration has been introduced to establish the initial schema. The 'up' script creates a 'users' table containing fields for user\_id, firstname, lastname, email, and password, while the 'down' script provides the corresponding drop statement to reverse the change.

migrations · high confidence

Dependencies

Initial Go module and dependency configuration

The project's Go module file (go.mod) and its checksum file (go.sum) have been added, establishing the project's dependencies. This includes the Go 1.17 version requirement and a set of direct dependencies such as the Gin web framework, the goqu SQL library, and the pgx PostgreSQL driver, along with their respective indirect dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 54 → 51 (-3.6)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (-0.5)
  • Architecture 100 → 69 (-31.0)
  • Maturity 71 → 63 (-8.2)
  • Readiness 17 → 25 (+7.8)
  • Security 100 → 90 (-10.5)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (8)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (internal/user/impl/repository.go)
  • Duplicated block (12 lines × 2) (internal/auth/impl/service.go)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • single-maintainer — knowledge-concentration (bus factor) risk

New (31)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/jackc/pgerrcode
  • Dependency pinned to a stale untagged commit: golang.org/x/crypto
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no project overview (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10–11 lines × 2) (internal/user/impl/repository.go)
  • Duplicated block (11 lines × 2) (internal/auth/impl/service.go)
  • Duplicated block (12 lines × 2) (internal/base/crypto/impl/crypto.go)
  • Duplicated block (6 lines × 2) (internal/user/impl/repository.go)
  • Duplicated block (9 lines × 2) (internal/user/impl/repository.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • …and 11 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

pvarentsov/go-backend-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0b047a95b1864286870b8b03ea7e30686dcee171 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.