Skip to content
CAI
Software that uses CAICheck a score

quangdangfit/goshop

56.5

Adequate · 21 September 2026

12.4k

lines of production code

Go

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

GoShop is a multi-domain e-commerce platform that manages product catalogs, user accounts, and order lifecycles through a unified API server exposing both HTTP and gRPC endpoints. It handles the complete checkout flow by integrating with Stripe for payments, enforcing atomic stock reservations to prevent overselling, and applying coupon discounts. The system also supports granular user notification preferences and delivers email alerts via SMTP with retry logic and dead-letter tracking.

How it got here

2020–2023 — Core domain and API implementation

26 changes.

The project established its foundational architecture by defining domain models for users, products, and orders, alongside implementing the corresponding HTTP and gRPC service layers. It introduced critical business logic for authentication, inventory management with stock reservations, and coupon-based checkout workflows. The period also focused on standardizing infrastructure through unified error handling, database wrappers, and Redis caching abstractions.

2026 — Domain modeling and payment integration

22 changes.

The project established strict domain boundaries by replacing generic data copying with explicit typed models and converters across product, user, and order modules. Concurrently, it integrated Stripe for payment processing and implemented a robust notification system with email support, retry logic, and user preferences. The period also saw the introduction of a client-side cart, a React web frontend, and an in-process event bus to decouple domain logic.

Features

Add gRPC API for user authentication and profile management

This change introduces a new gRPC service implementation for the User domain, exposing endpoints for login, registration, retrieving the current user profile (GetMe), refreshing access tokens, and changing passwords. The implementation includes the gRPC server registration logic, request/response handlers that bridge the protobuf definitions to the internal service layer, and data converters that map internal user models to the gRPC UserInfo structure while safely excluding sensitive fields like passwords. Comprehensive unit tests are provided for both the handler logic and the server registration to ensure correct behavior and error handling.

internal/user/port/grpc · high confidence

Add gRPC server with authentication and graceful shutdown

The application now exposes a gRPC server that registers user, product, and order service handlers. Authentication is handled via a configurable interceptor that switches between standard auth and OIDC based on the configuration. The server supports graceful shutdown to ensure clean termination.

internal/server/grpc · high confidence

Added user notification preferences and dead-letter tracking models

The system now supports per-user notification preferences, allowing users to toggle specific event types for specific channels (e.g., email), with a default behavior of being fully opted in. Additionally, a dead-letter model has been introduced to audit notifications that have exhausted their retry budget, enabling operators to inspect delivery failures and trigger manual replays. Both models include automatic ID generation via GORM hooks.

internal/notification/model · high confidence

Configurable authentication modes and OIDC integration

The application now supports switching between legacy JWT authentication and OIDC via Authentik through a new \auth\_mode\ configuration option. This change introduces a centralized configuration schema (\pkg/config\) that loads settings from environment variables and YAML files, covering database, Redis, Stripe, SMTP, and the new Authentik OIDC parameters (issuer, client credentials, JWKS URL). A new \pkg/oidc\ package provides an OIDC validator to handle provider discovery, ID token verification, and OAuth2 authorization code flows. The configuration also defines specific gRPC methods to ignore for authentication checks, allowing unauthenticated access to login and registration endpoints.

pkg/config · high confidence

Coupon support and stock reservation lifecycle in order service

The order service now supports applying coupons during checkout, calculating fixed or percentage discounts while enforcing expiration, usage limits, and minimum order amounts. Placing an order atomically reserves stock and creates stock reservations that hold inventory for 15 minutes until payment clears or a sweeper releases them. When an order is marked paid, reservations are committed and a LowStock event is published if available stock falls to or below 5, enabling admin alerts and frontend badges. The sweeper tolerates orphaned reservations and already-released counters, releasing stock and canceling orders without failing. Cancellation releases active reservations and returns stock. An InsufficientStockError is surfaced on checkout so the frontend can reconcile the cart with a 409 response.

internal/order/service · high confidence

Database-backed notification preferences with opt-in defaults

Users can now manage their notification preferences (per event and channel) via a new database-backed service. The system uses an opt-in default policy: if a user's preference is not explicitly set, or if the database/user lookup encounters an error, notifications are enabled by default to ensure delivery is not silenced by transient outages. This change introduces the preference storage and lookup logic within the notification service, including the adapter for user lookups.

internal/notification/service · high confidence

HTTP endpoints for user notification preferences

Users can now manage their notification settings via new HTTP endpoints. The system exposes a GET /me/notification-preferences route to retrieve current preferences and a PUT /me/notification-preferences route to update specific event-channel combinations (e.g., enabling email notifications for order payments). These endpoints are protected by JWT authentication and are wired into the application's API router.

internal/notification/port · high confidence

HTTP server with graceful shutdown and unified route registration

The HTTP server now supports graceful shutdown via a new Shutdown method, allowing the application to stop accepting new requests and wait for in-flight requests to complete. The server registers routes for user, product, order, payment, and notification APIs under /api/v1, and exposes a /health endpoint for health checks. Swagger documentation is available at /swagger/\*any. The server uses Gin as the HTTP framework and integrates with middleware for CORS and rate limiting.

internal/server/http · high confidence

Initial database seed script for development environments

A new seed script (scripts/seed.sql) has been added to populate the database with initial reference data for local development. This includes six product categories (Electronics, Clothing, Home & Kitchen, Sports & Outdoors, Books, Beauty & Health) and 25 sample products, each associated with placeholder images from picsum.photos. The script also inserts two default user accounts (customer and admin) with pre-hashed passwords for immediate testing access.

scripts · high confidence

Initial gRPC API contracts for User, Product, and Order services

This change introduces the foundational gRPC interface definitions for the application's core domains. It adds Protocol Buffer schemas and the corresponding Go code generation configuration (buf.yaml, buf.gen.yaml) for three services: UserService (handling registration, login, profile retrieval, and password changes), ProductService (managing product creation, updates, and listing), and OrderService (supporting order placement, retrieval, and cancellation). This establishes the contract for inter-service communication and client-server interaction for these features.

proto · high confidence

Initial web client setup with Vite, React, and Tailwind CSS

The web directory now contains a complete frontend application scaffolded with Vite and React, utilizing Tailwind CSS for styling and TypeScript for type safety. This setup includes configuration for client-side routing via an Nginx container (with SPA fallback), API proxying to localhost:8888 during development, and a test environment using Vitest with jsdom. The project structure supports features such as cart management, authentication, product browsing, and checkout, as indicated by the included source files and API clients.

web · high confidence

Introduce Redis client abstraction with JSON serialization and mock support

Added a new \pkg/redis\ package that provides a \Redis\ interface wrapping \go-redis/v9\, enabling services to interact with Redis through a standardized contract. The implementation automatically marshals and unmarshals values to/from JSON, handles connection timeouts, and includes specific methods for incrementing keys with expiration (\Incr\), pattern-based deletion (\RemovePattern\), and connection health checks (\IsConnected\). A generated mock (\pkg/redis/mocks/Redis.go\) and comprehensive unit tests using \miniredis\ are included to facilitate testing of dependent components.

pkg/redis · high confidence

Introduce in-process event bus for domain decoupling

Added a lightweight, in-process pub/sub event bus (pkg/eventbus) to decouple domain logic from notification transports. The bus supports typed events including OrderCreated, OrderPaid, OrderCancelled, and LowStock, allowing subscribers to react asynchronously without blocking the publisher. It provides a global singleton via Default() for easy integration and SetDefault() for test isolation, with handlers running on detached goroutines to ensure slow subscribers do not impact publish latency.

pkg/eventbus · high confidence

Introduce order model with status transitions and stock reservations

The order service now includes a complete domain model for managing orders, including status transition logic (e.g., new → pending\_payment → paid → in-progress → done/cancelled), coupon support, and stock reservation tracking. This enables the system to enforce valid order lifecycles, apply discounts, and reserve inventory during the payment process, with idempotent creation hooks to prevent duplicate lines on save.

internal/order/model · high confidence

Introduce payment model with automatic ID generation and webhook deduplication

The system now includes a local Payment model that automatically assigns a unique ID and sets the initial status to 'pending' when a new record is created, ensuring consistent state for charge attempts. Additionally, a ProviderEvent model is introduced to handle webhook deliveries, using a unique index on provider and event ID to guarantee exactly-once processing of external events. Tests verify that the BeforeCreate hook correctly generates IDs and preserves existing fields.

internal/payment/model · high confidence

Introduce user, address, and wishlist domain models with automatic ID generation and password hashing

The internal user model package now defines core domain entities: User, Address, and Wishlist. The User model supports role-based access (admin/customer) and automatically hashes passwords upon creation, while defaulting new users to the 'customer' role. Both Address and Wishlist models are introduced to support user profile data and saved items, respectively, with all three models automatically generating unique UUIDs for their primary keys before database insertion. Comprehensive unit tests verify the BeforeCreate hooks for ID generation, password hashing, and role assignment.

internal/user/model · high confidence

Introduces GoShop API server with graceful shutdown and stock reservation sweeper

The application now starts a unified API server that runs both HTTP and gRPC endpoints concurrently. On startup, it initializes a process-wide event bus that logs low-stock warnings and connects to Redis for caching. A background sweeper runs every 60 seconds to release expired stock reservations and cancel associated unpaid orders. The server handles graceful shutdown, waiting up to 30 seconds for active HTTP requests to complete and ensuring the gRPC server stops cleanly before exiting.

cmd · high confidence

Introduces structured error handling and unified authentication middleware for HTTP and gRPC

This change introduces a new \apperror\ package that standardizes application errors with structured codes, HTTP status mappings, and gRPC code mappings, ensuring consistent error responses across both HTTP and gRPC interfaces. It adds middleware components for JWT and OIDC (Authentik) authentication, providing unified user context injection for both HTTP handlers and gRPC interceptors. Additionally, it includes middleware for admin-only access control, CORS handling, and rate limiting with specific exemptions for webhook endpoints to prevent payment confirmation issues.

pkg/middleware · high confidence

JWT token generation and validation added

The application now includes a dedicated package for handling JSON Web Tokens, providing functions to generate access tokens (valid for 5 hours) and refresh tokens (valid for 30 days) using HS256 signing. It also implements token validation that strips the 'Bearer' prefix, verifies signatures against the configured auth secret, checks expiration, and extracts the payload. Comprehensive tests cover valid tokens, Bearer prefix handling, invalid tokens, non-object payloads, wrong secrets, expired tokens, and signing errors.

pkg/jtoken · high confidence

New database wrapper package with GORM integration

A new \pkg/dbs\ package has been added, providing a \Database\ interface and implementation that wraps GORM with PostgreSQL. This component introduces a unified API for database operations including CRUD actions, batch creation, and transaction management. It supports flexible query construction via functional options for filtering, ordering, pagination, and preloading, and enforces a 5-second timeout on all database contexts. Comprehensive unit tests using \sqlmock\ verify the behavior of these database interactions.

pkg/dbs · high confidence

New email notification channel with retry, dead-letter, and per-user preferences

The notification system now supports sending order-related emails via SMTP. Users can configure SMTP credentials to enable this channel, which is layered alongside the existing logger-based notifier. Delivery respects per-user preferences (allowing users to opt out of specific event types), and failed deliveries are automatically retried with exponential backoff; messages that exhaust retries are sent to a dead-letter queue for later inspection. The implementation includes a new \Notifier\ interface, an \EmailSender\ for SMTP transport, a \PreferenceChecker\ for filtering, and a \RetryingNotifier\ wrapper, all wired together via a factory that builds the appropriate chain based on configuration.

pkg/notification · high confidence

New pagination helper for consistent API response structure

A new \pkg/paging\ package has been added to provide a standardized way to handle pagination logic for API responses. The \New\ function calculates total pages, skip offsets, and current page numbers, enforcing a default page size of 20 and capping custom page sizes at this limit. This ensures consistent pagination metadata (current page, total items, total pages, limit, skip) is returned to users across list endpoints.

pkg/paging · high confidence

New utility functions for object copying, code generation, and password hashing

Added three new utility functions to the \pkg/utils\ package: \Copy\ for deep-copying objects via JSON marshaling, \GenerateCode\ for creating alphanumeric codes with date-based prefixes, and \HashAndSalt\ for securely hashing passwords using bcrypt. Comprehensive table-driven unit tests were added for all three functions to verify their behavior across various input scenarios.

pkg/utils · high confidence

Order service now exposes gRPC and HTTP ports with coupon management and stock conflict handling

The order module now provides a complete set of transport ports: a new gRPC interface (handlers, converters, and server registration) alongside the existing HTTP endpoints. The HTTP API now includes coupon management routes (create and lookup) and returns HTTP 409 Conflict when stock is insufficient during order placement. Both ports enforce authentication, validate inputs, and wire up the order service with reservation, coupon, and notification dependencies.

internal/order/port · high confidence

Payment repository with idempotent webhook event handling

The payment repository now includes a RecordProviderEvent method that ensures webhook processing is idempotent by tracking provider events; if a duplicate event is detected, it returns a specific ErrEventAlreadyProcessed error rather than failing with a database constraint violation. This change supports reliable Stripe integration by preventing duplicate processing of payment events.

internal/payment/repository · high confidence

Product gRPC service implementation and error handling

The product gRPC port now exposes standard CRUD operations (GetProductByID, ListProducts, CreateProduct, UpdateProduct) via a new ProductHandler. This handler maps incoming gRPC requests to the domain service layer and handles response serialization using utils.Copy. Crucially, the implementation now explicitly checks for errors during this copy process (e.g., when handling NaN values in prices), ensuring that internal data conversion failures are propagated as gRPC errors to the client rather than causing panics or silent data corruption. The service is registered via RegisterHandlers, wiring the repository, service, and handler together.

internal/product/port/grpc · high confidence

Product repository now supports atomic stock decrement and admin restock

The product repository in \internal/product/repository\ has been updated to include two new stock-management capabilities: \DecrementStock\ and \AddStock\. \DecrementStock\ performs an atomic database update that only succeeds if sufficient stock is available (checking \stock\_quantity - reserved\_quantity\), returning an error if stock is insufficient, which supports safe order processing. \AddStock\ atomically increases the stock quantity, supporting the admin restock workflow. The repository interface and its generated mocks have been updated to expose these methods, and unit tests have been added to verify the new behavior.

internal/product/repository · high confidence

Stripe payment integration with idempotent intent creation and webhook handling

The payment service now integrates with Stripe using PaymentIntents. The \CreateIntentForOrder\ method ensures the client secret is always non-empty by replaying the intent creation via Stripe's idempotency key on every call, rather than relying solely on stored database records. The \HandleWebhook\ method verifies signatures, deduplicates events, and updates payment status (succeeded, failed, canceled, processing, requires action) while triggering corresponding order status changes.

internal/payment/service · high confidence

Stripe payment integration with webhook handling

The payment port now integrates with Stripe, exposing an authenticated endpoint to create PaymentIntents for orders and a public webhook endpoint to process Stripe callbacks. The webhook handler verifies the Stripe-Signature header to ensure request authenticity before processing. Additionally, a public configuration endpoint exposes the Stripe publishable key and the current authentication mode to the frontend.

internal/payment/port · high confidence

Stripe payment integration with webhook verification

The payment package now includes a new Stripe provider implementation that creates PaymentIntents via Stripe's REST API and verifies incoming webhook signatures using HMAC-SHA256. This allows the system to process payments and handle status updates (succeeded, failed, canceled, processing, requires\_action) while rejecting unverified or stale webhook events.

pkg/payment · high confidence

Support for per-user notification preferences and dead-letter storage

Users can now manage granular notification preferences (per user, event type, and channel) via a new repository that supports listing, retrieving, and upserting these settings. Additionally, a dead-letter sink has been introduced to persist notifications that have exhausted their retry attempts, ensuring that failed delivery attempts are recorded for later inspection rather than being silently dropped.

internal/notification/repository · high confidence

Behavioural changes

HTTP handlers for products, categories, and reviews now use domain types and explicit error handling

The HTTP layer for the product module has been refactored to use the new \domain\ package for request/response models instead of the previous \dto\ package, and to handle conversion errors from \utils.Copy\ explicitly. Handlers for products, categories, and reviews now return HTTP 500 errors when model-to-domain copying fails (e.g., due to invalid data like NaN prices), rather than silently failing or panicking. This change ensures that users receive proper error responses for malformed internal data during product, category, and review operations.

internal/product/port/http · high confidence

Headless Authentik authentication via flow executor

The application now supports headless authentication with Authentik by implementing a dedicated HTTP client that interacts with the Authentik flow executor API. This allows the application to handle password-based login (ROPG) and user registration programmatically without relying on browser-based SSO redirects, while still supporting OIDC for federated identity lookups. The change introduces a new client package that manages session cookies and flow stages to verify credentials and provision users server-side.

pkg/authentik · high confidence

Introduce atomic stock reservation lifecycle for order fulfillment

The order repository now supports a three-step inventory management process: ReserveStock atomically increments a reserved\_quantity counter if sufficient stock is available, CommitReservation decrements both stock and reserved counters to finalize a sale, and ReleaseReservation returns reserved units to available stock. This replaces the previous simple DecrementStock approach, allowing orders to hold inventory during the payment window and preventing overselling. The repository also includes new implementations for coupon usage tracking, order listing with newest-first default sorting, and comprehensive unit tests for the new reservation state machine.

internal/order/repository · high confidence

Introduce client-side cart with persistent localStorage storage

The shopping cart is now managed entirely on the client side using a new \cartStore\ backed by \localStorage\ (key \goshop:cart:v1\), removing the previous server-side cart persistence. This change introduces a schema-versioned storage format to handle future shape changes, a stable snapshot mechanism via \useSyncExternalStore\ to prevent infinite React render loops, and cross-tab synchronization using the \storage\ event. The cart now stores a snapshot of product details (name, price, images, stock) at the time of addition for offline display, while the server re-validates price and stock at order time. Existing API endpoints and UI components (CartPage, ProductCard, Navbar) have been updated to interact with this new client-side store.

web/src · high confidence

Introduce typed domain models and explicit converters for the product module

The product module now defines explicit domain types for Categories, Products, and Reviews, along with corresponding request and response structures, replacing the previous generic or implicit data handling. To support this, new typed converter functions have been added to map between internal storage models and these domain types, eliminating the previous reliance on a generic \utils.Copy\ utility that performed JSON round-trip conversions. This change ensures type safety and clearer data boundaries within the product domain layer.

internal/product/domain · high confidence

New product domain models for categories, products, and reviews

The product model layer now includes structured domain entities for Categories, Products, and Reviews, replacing previous ad-hoc or generated structures. Products now support image storage via a JSON-serialized list, track reserved stock quantities for atomic order processing, and automatically generate unique codes and IDs upon creation. Categories and Reviews are also defined with their own schemas, including soft-delete support and unique constraints, providing a more robust foundation for the product catalog and user feedback features.

internal/product/model · high confidence

Product service implements domain-driven design with comprehensive unit tests

The product service has been refactored to follow a domain-driven design (DDD) architecture, moving request objects from a DTO package to a dedicated domain package and introducing typed converters. This change introduces new service interfaces and implementations for managing categories, products, and reviews, including specific capabilities such as atomic stock restocking with admin audit logging and automatic recalculation of product ratings when reviews are created, updated, or deleted. To support this new structure, the update includes generated mocks for service interfaces and extensive table-driven unit tests covering success paths, validation failures, database errors, and permission checks.

internal/product/service · high confidence

Replace automatic schema migration with versioned SQL files

The application no longer automatically applies schema changes on startup via AutoMigrate. Instead, the database schema is now managed through explicit, versioned SQL migration files (using golang-migrate), starting with an initial schema that creates 14 tables including users, products, orders, and payments. Users must now run migrations manually (e.g., via \migrate up\) before or during deployment, rather than relying on the application to handle schema updates automatically.

migrations · high confidence

Standardized HTTP response and error handling

The application now uses a unified response structure for all API interactions, wrapping data in a consistent JSON envelope with 'result' and 'error' fields. Error handling has been centralized to automatically map application errors to appropriate HTTP status codes and user-facing messages, while also supporting environment-aware behavior to hide debug details in production.

pkg/response · high confidence

User HTTP handlers and routes restructured for Domain-Driven Design

The HTTP layer for the user module has been rewritten to align with the new DDD architecture. This introduces dedicated handlers for user authentication (login, register, profile, password change), address management (CRUD and default selection), and wishlist operations (add, remove, list). A new telemetry endpoint allows clients to submit cart snapshots for analytics without affecting order construction. The routing configuration now conditionally initializes an Authentik OIDC client when operating in headless OIDC mode, while maintaining local JWT-based session management for protected routes.

internal/user/port/http · high confidence

User domain models and typed converters introduced

The internal user domain now defines explicit structs for User, Address, and WishlistItem, along with request/response types for authentication and wishlist operations. A new typed converter layer replaces the previous generic copying utility, ensuring that internal fields like passwords are safely excluded from API responses and eliminating unreachable error branches.

internal/user/domain · high confidence

User repository layer refactored to Domain-Driven Design with new address and wishlist persistence

The user repository implementation has been restructured to follow Domain-Driven Design principles, introducing dedicated repositories for user addresses and wishlists alongside the existing user repository. The new AddressRepository provides methods to list, retrieve, create, update, delete, and set default addresses for a user, while the WishlistRepository enables adding, removing, and retrieving wishlist items. The UserRepository remains responsible for basic user creation, updates, and lookups by ID or email. All repository interfaces are now backed by generated mocks to support unit testing, and comprehensive table-driven tests have been added for each repository to verify success and error scenarios.

internal/user/repository · high confidence

User service refactored to support headless Authentik OIDC authentication

The user service now supports two authentication modes: the existing local password-based flow and a new headless OIDC mode powered by Authentik. When configured, login and registration operations delegate credential validation and user provisioning to the Authentik client (via PasswordLogin and CreateUser APIs) instead of using local bcrypt checks, while still issuing internal GoShop JWTs. The service layer has been restructured into distinct Address, User, and Wishlist services with corresponding unit tests and generated mocks, and DTO packages have been renamed to domain.

internal/user/service · high confidence

Fixes

Introduce explicit domain models and converters for orders and coupons

The internal order domain now uses explicit DTO structs (Order, Coupon, OrderLine, Product) and dedicated conversion functions (e.g., OrderFromModel, CouponFromModel) instead of relying on a generic utils.Copy. This removes unreachable error branches from JSON-roundtrip conversions and ensures internal columns like deleted\_at are hidden from API responses. Tests verify correct mapping, including nil handling and nested product data.

internal/order/domain · high confidence

Test coverage

Added generated mock implementations for database interfaces; New integration test suites for core domain features.

Dependencies

Initial dependency manifests for Go backend and React frontend

The project now includes its first dependency manifests: a Go module file (go.mod) and a web package file (web/package.json) with corresponding lockfiles. The Go backend specifies Go 1.26 and includes libraries for the Gin web framework, GORM with a PostgreSQL driver, Redis caching, gRPC, OIDC authentication, and SQL migrations. The React frontend defines dependencies for React 18, React Router, TanStack Query, and form validation, along with development tools like Vite, TypeScript, and Vitest.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 59 → 57 (-2.8)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 85 → 86 (+1.1)
  • Architecture 100 → 78 (-21.9)
  • Maturity 69 → 69 (-0.1)
  • Readiness 56 → 49 (-6.6)
  • Security 51 → 62 (+11.1)
  • Domain Modelling 100 → 82 (-18.4)
  • Event-Driven 78 (new)
  • Accessibility 68 → 55 (-13.6)

Resolved (57)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (web/package-lock.json)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (internal/order/port/grpc/handlers.go)
  • Duplicated block (11 lines × 2) (internal/order/repository/order.go)
  • Duplicated block (11 lines × 3) (internal/product/port/http/handlers.go)
  • Duplicated block (12 lines × 2) (internal/order/port/grpc/server.go)
  • Duplicated block (14 lines × 2) (internal/order/port/http/handlers.go)
  • Duplicated block (8 lines × 2) (internal/order/repository/product.go)
  • Duplicated block (9 lines × 2) (pkg/redis/redis.go)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High vulnerability: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 37 more

New (147)

  • AdminCategoriesPage.AdminCategoriesPage (cognitive 17) (web/src/pages/admin/AdminCategoriesPage.tsx)
  • AdminCategoriesPage.AdminCategoriesPage (cyclomatic 19) (web/src/pages/admin/AdminCategoriesPage.tsx)
  • AdminCouponsPage.AdminCouponsPage (cyclomatic 20) (web/src/pages/admin/AdminCouponsPage.tsx)
  • AdminProductsPage.AdminProductsPage (cognitive 20) (web/src/pages/admin/AdminProductsPage.tsx)
  • AdminProductsPage.AdminProductsPage (cyclomatic 22) (web/src/pages/admin/AdminProductsPage.tsx)
  • CheckoutPage.CheckoutPage (cognitive 38) (web/src/pages/CheckoutPage.tsx)
  • CheckoutPage.CheckoutPage (cyclomatic 37) (web/src/pages/CheckoutPage.tsx)
  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (web/package-lock.json)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency advisory scan runs only on code events
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (internal/order/port/http/handlers.go)
  • Duplicated block (10 lines × 2) (internal/order/repository/order.go)
  • Duplicated block (10 lines × 3) (internal/order/port/http/handlers.go)
  • Duplicated block (11 lines × 2) (internal/order/port/http/handlers.go)
  • Duplicated block (12 lines × 3) (internal/product/port/http/handlers.go)
  • Duplicated block (13–14 lines × 2) (internal/order/port/grpc/server.go)
  • …and 127 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

quangdangfit/goshop was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2a6b87c6afdea70415c5660f061f229b52d1337d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.