rafael-piovesan/go-rocket-ride
59.5
Adequate · 21 September 2026
1.4k
lines of production code
Go
primary language
4
measurements over time
What this system is
Features
Add PostgreSQL container helper for testing
A new helper function, NewPostgresContainer, has been added to the testcontainer package. This function spins up a PostgreSQL 14.1 container, waits for it to be ready, and returns the connection string (DSN) along with a cleanup function. The implementation includes a dependency on the Bun PostgreSQL driver to ensure the driver is loaded for tests.
pkg/testcontainer · high confidence
Add Postgres database connection and repository layer
Introduces a new \pkg/db\ package that provides a Postgres database connection using the \bun\ ORM and \pgdriver\. The \Connect\ function initializes the database client, and \ConnectionHandle\ exposes the underlying \bun.IDB\ interface for repository usage.
pkg/db · high confidence
Add Stripe mock integration for local testing
The \pkg/stripemock\ package now provides a \stripe-mock\ integration that configures the Stripe Go SDK to communicate with a local mock server. This includes an \Init()\ function that validates the mock server is running and meets the minimum version (0.109.0), and an \InitForError()\ function that simulates a 402 payment error for testing error handling.
pkg/stripemock · medium confidence
Add application configuration loader
A new \pkg/config\ package has been introduced to centralize application configuration. It uses Viper to read settings from an \app.env\ file or environment variables, covering \IDEM\_KEY\_TIMEOUT\, \DB\_SOURCE\, \SERVER\_ADDRESS\, and \STRIPE\_KEY\. The configuration is validated using the go-playground/validator library, ensuring required fields are present.
pkg/config · high confidence
Add generic CRUD store for database operations
A new generic CRUD store has been introduced in the data package, providing a unified interface for Create, Read, Update, and Delete operations on database models. This implementation leverages the Bun ORM to offer reusable FindAll, FindOne, Save, Update, and Delete methods that work with any typed model, simplifying data access layer logic across the application.
pkg/data · medium confidence
Add new entity definitions for audit and staged jobs
Introduced new Go packages for domain entities. The \entity/audit\ package defines constants and stringer methods for ride-related actions and resource types. The \entity/stagedjob\ package defines constants for job names and a struct for receipt arguments, supporting the system's background job processing.
entity/audit, entity/stagedjob · high confidence
Add origin IP entity for request context propagation
A new \originip\ package introduces an \OriginIP\ struct and associated context helpers (\NewContext\, \FromCtx\) to store and retrieve the client's IP address within the request context. This allows downstream components to access the origin IP via the context, with a fallback to a default IP if not found.
entity/originip · high confidence
Add ride usecase with idempotency and Stripe integration
The ride usecase now implements a multi-step workflow (create ride, create charge, send receipt) protected by an idempotency key mechanism to prevent duplicate processing. The implementation includes locking and unlocking of idempotency keys, parameter validation to ensure consistent requests, and integration with Stripe for payment processing. Unit tests have been added to verify the idempotency logic and mock Stripe interactions.
usecase · high confidence
Added PostgreSQL migration and test fixture helpers
New helper functions were added to the codebase to simplify database operations. The \pkg/migrate\ package now provides an \Up\ function that executes PostgreSQL migrations from a specified source path. Additionally, the \pkg/testfixtures\ package introduces a \Load\ function that populates a PostgreSQL database with test data using YAML-based fixtures, supporting template data injection.
pkg/migrate, pkg/testfixtures · high confidence
Initial database schema and test fixtures
The database layer now includes the initial set of SQL migrations that define the core data model: idempotency keys, users, audit records, rides, and staged background jobs. Additionally, YAML fixture files are provided for local development and testing, containing sample data for idempotency keys, users, and rides to support consistent test environments.
db · high confidence
Introduce API layer with middleware and handlers
The API layer is introduced, providing the HTTP entry point for the application. This includes middleware for user authentication (via the 'Authorization' header), idempotency key validation, and error mapping. The 'ride' handler implements the 'Create' endpoint, which validates request parameters and invokes the use case. Tests are added to verify the behavior of the middleware and handlers.
api · high confidence
Introduce a unit-of-work pattern for atomic database transactions
The datastore package has been refactored to use a generic CRUD store interface (data.ICRUDStore) for entities like AuditRecord, IdempotencyKey, Ride, StagedJob, and User. Additionally, a new Unit-of-Work implementation (datastore/uow) has been added to wrap multiple store operations within a single database transaction, ensuring that changes to AuditRecord, IdempotencyKey, Ride, StagedJob, and User are committed or rolled back together.
datastore · high confidence
Introduce idempotency entity definitions
A new Go package for idempotency has been added, defining constants for recovery points (STARTED, CREATED, CHARGED, FINISHED) and HTTP response codes (OK, Conflict, Payment Required, Service Unavailable) along with a response body structure. This provides a centralized set of constants and types for handling idempotency states and associated HTTP responses.
entity/idempotency · high confidence
Introduce new HTTP server package
A new \pkg/httpserver\ package has been added, providing an \echo\-based HTTP server setup. It includes a \New\ function that configures the Echo router with logging, recovery, and a custom error handler that maps errors to appropriate HTTP status codes and JSON responses. The \fx.go\ file integrates the server lifecycle with the application's dependency injection framework, starting the server on startup and handling graceful shutdown with a 10-second timeout.
pkg/httpserver · high confidence
Introduces new domain entity models
The application now defines a set of new entity structs in the entity package, including AuditRecord, IdempotencyKey, Ride, StagedJob, and User, each with their respective fields and database tags. Additionally, a collection of predefined error variables (such as ErrPermissionDenied, ErrNotFound, and ErrIdemKeyParamsMismatch) is added to the entity package to standardize error handling across the domain.
entity · high confidence
Project setup and development workflow improvements
The repository now includes a Taskfile to streamline development tasks such as running the API server, executing unit and integration tests, and managing database migrations. A .golangci.yaml configuration file has been added to standardize code linting and formatting. Additionally, the project provides an app.env.sample file for environment configuration, a docker-compose.yaml to easily spin up local Postgres and Stripe mock services, and an app.http file for quick API testing. The README has been expanded with detailed setup instructions, architecture overview, and IDE configuration tips.
(repo-wide) · high confidence
Behavioural changes
Introduce fx-based dependency injection and unit tests for the API entry point
The cmd/api/main.go file has been refactored to use the fx framework for dependency injection, wiring up configuration, database connections, the unit-of-work pattern, and HTTP server initialization. Corresponding unit tests in cmd/api/main\_test.go have been added to verify that the application correctly validates required environment variables (DB\_SOURCE, SERVER\_ADDRESS) and handles invalid configurations gracefully.
cmd · high confidence
Test coverage
Added mock implementations for datastore and usecase interfaces
Added autogenerated mock types for the datastore layer (AuditRecord, IdempotencyKey, Ride, StagedJob, UnitOfWork, UnitOfWorkBlock, UnitOfWorkStore, and User) and the usecase layer (Ride). These mocks, generated by mockery v2.12.2, provide test doubles for repository and use-case interfaces, enabling unit tests to simulate database interactions and business logic without relying on real implementations.
mocks · high confidence
Dependencies
Updated Go dependencies for v2 release
The project's go.mod and go.sum files have been updated with a new set of dependencies, including libraries for testing (testcontainers, testify), configuration (viper), database migration (golang-migrate), and various indirect dependencies. This reflects the transition to version 2 of the project.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 54 → 60 (+5.2)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 100 → 69 (-31.0)
- Maturity 58 → 58 (+0.0)
- Readiness 59 → 67 (+8.5)
- Security 91 → 73 (-18.8)
- Domain Modelling 38 → 53 (+14.9)
Resolved (7)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- No exposed public API
- OSV Dependency Vulnerabilities not included (check did not complete)
- Test reliability not included
- The 'Architecture & code organization' section is cut off by the scanner mid-sentence ('Midway through each API request...'), so its full outline (setup, download/install both project and dev dependencies, start dependencies, run db migrations, load fixtures) cannot be confirmed from the visible text. (README.md)
- dormant codebase — no living knowledge left to concentrate
New (52)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: golang.org/x/net
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High IaC: WD-COMPOSE-0002 (docker-compose.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 32 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
rafael-piovesan/go-rocket-ride was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 50476d0f2c0e5d91d87d3a9134ce9ad532c3b01e — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.