Skip to content
CAI
Software that uses CAICheck a score

samverrall/go-task-application

54.3

Adequate · 21 September 2026

1.5k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add SQLite-backed user repository with tests

Added a new SQLite-based implementation of the user repository, providing persistence for user data using GORM. This includes the repository interface implementation, utility functions for mapping between domain and GORM models, and a comprehensive test suite that validates user creation and retrieval by ID and email.

user-service/internal/adapters/right · high confidence

Add gRPC server and GetUserEmail endpoint for user service

The user-service now exposes a gRPC interface to handle client requests. A new gRPC server is registered to listen on a configurable host and port, and implements the GetUserEmail method, which retrieves a user's email address and returns it via a dedicated response DTO. The implementation includes error handling for missing users and logging for debugging.

user-service/internal/adapters/left · high confidence

Add gateway-service configuration infrastructure

The gateway-service now includes a dedicated configuration module that loads and parses YAML settings using the Viper library. This introduces a new config file (local.config.yaml) that defines the user-service endpoint details, specifically the host (127.0.0.1) and port (8002).

gateway-service/config · high confidence

Add shared gRPC and HTTP API definitions for user services

The task-application-proto module now includes a shared protobuf definition for a User service that exposes a gRPC endpoint and an HTTP/REST endpoint (GET /v1/api/users/{user\_uuid}) to retrieve a user's email. This change introduces the proto schema, the generated Go code (including gRPC client/server stubs and grpc-gateway reverse-proxy handlers), and the corresponding OpenAPI/Swagger 2.0 documentation, enabling the user-service to proxy requests through the gateway.

task-application-proto · high confidence

Added shared utility functions for background execution, HTTP responses, and pointer handling

New utility functions have been introduced to standardize common operations across the application. The background package provides a Go routine wrapper that safely handles panics in background goroutines. The http package adds a helper to encode and write JSON responses with a specific status code. The pointer package offers generic functions to create pointers to values and safely dereference them, returning a zero value if the pointer is nil.

utils · high confidence

Introduce HTTP server, middleware, and health check for the gateway service

The gateway service now includes a dedicated HTTP server implementation that handles incoming requests and proxies them via gRPC. This change introduces a new server package containing the HTTP server setup, a /healthz endpoint for health checks, and middleware for logging, CORS handling, and request body size limiting (max 100KB for POST/PUT/PATCH). Users will see a functional HTTP interface on the gateway service with health monitoring and standardized error responses.

gateway-service/server · high confidence

Introduce HTTP-to-gRPC proxy gateway for user-service

A new gateway service has been added to the application, providing an HTTP interface that proxies requests to the user-service via gRPC. The implementation includes a HTTP handler that registers the user-service endpoint and a response modifier that translates gRPC metadata (specifically the HTTP status code) into the HTTP response, ensuring that internal gRPC headers are not exposed to the client.

gateway-service/gateway · high confidence

Introduce task creation service and repository interfaces

Added a new task creation service that validates task names and complete-by dates, and defines a TaskRepo interface for persisting tasks. The service layer (task.go, create\_task.go) coordinates domain validation and repository calls, while the repository layer (repositories.go, task.go) provides the interface, domain models, and SQLite implementation with automatic database migration. A mock repository and shared test helpers are also included to support testing implementations.

task-service/internal/port · high confidence

User registration and retrieval via gRPC

The user-service now supports registering new users and retrieving user details via gRPC. This change introduces domain models for email and hashed passwords, a repository interface for user data, and service implementations for user registration and user lookup. The registration flow validates email format and password length, hashing the password before storage. The get user flow enforces an authorization guard to ensure the caller is permitted to retrieve user data. Tests confirm that invalid emails, short passwords, and unauthorized access are correctly rejected.

user-service/internal/port · high confidence

Behavioural changes

Gateway service HTTP server and configuration entry point

The gateway service now includes a new command-line entry point (main.go) that initializes the HTTP server, loads configuration from a YAML file, and starts the gateway handler. This change introduces the server startup logic, including graceful shutdown handling and configurable host/port defaults (127.0.0.1:5000).

gateway-service/cmd · medium confidence

Introduce Argon2 password hashing in user-service

The user-service now implements secure password hashing using the Argon2 algorithm. A new \user-service/pkg/hasher\ package provides an \Argon2\ implementation that generates and verifies password hashes, utilizing \crypto/rand\ for secure salt generation. This change introduces the core hashing logic and its associated tests, while also restructuring the package layout by moving the SQLite connection logic to \user-service/pkg/sqlite\.

user-service/pkg · medium confidence

Logger module relocated to root directory

The shared logger module has been moved from the task-service package to the root logger directory, simplifying the project structure and making the logger more accessible across the application.

logger · low confidence

Removed legacy REST handler for task creation

The previous implementation of the REST endpoint for creating tasks has been removed from the codebase. This change eliminates the direct coupling between the HTTP handler and the domain model, paving the way for a more decoupled architecture using DTOs and a dedicated service package.

task-service/internal/rest · high confidence

Restructure task-service internal package layout

The task-service has been restructured to use a dedicated service package, moving the task service implementation from the api package to internal/app/api/task.go. This change also includes adding migrations for the SQLite task repository and updating the README to reflect the correct service name.

task-service · medium confidence

Restructured REST and SQLite repository adapters

The REST adapter for tasks has been reorganized into the new 'left' adapter layer, introducing a dedicated handler for creating tasks via a POST /api/tasks endpoint. The SQLite repository adapter has been added to the 'right' layer, implementing task persistence using GORM with automatic database migration. The REST server initialization was updated to accept the task service dependency directly rather than through a generic API interface, and middleware/handler registration has been consolidated into the Start method.

task-service/internal/adapters · medium confidence

Restructured task domain and repository layers

The task-service internal domain and repository layers have been restructured. The domain package now contains the Task struct and validation logic, while the repository package handles SQLite persistence. The previous domain\_repos.go file and task.go file in the domain package have been removed, and the task\_sqlite.go file in the repository package has been deleted, indicating a move towards using DTOs to keep the application decoupled.

task-service/internal/domain · medium confidence

Restructured task-service architecture and introduced SQLite repository

The task-service has been restructured to adopt a cleaner, layered architecture. A new SQLite database adapter has been added to the package, providing a connection and migration interface for the SQLite database. The main entry point has been refactored to initialize the SQLite repository, business logic, and REST API in a more explicit order, reflecting a shift towards a more modular and testable codebase. Additionally, the configuration package has been updated to support parsing configuration from a file, although the implementation is currently a placeholder.

task-service/cmd · high confidence

User-service gRPC server entry point and configuration

The user-service now exposes a gRPC server on port 8002 (default) and connects to a SQLite database. The entry point wires the gRPC adapter to the user business logic, which includes password hashing via Argon2.

user-service/cmd · medium confidence

Dependencies

Initialize Go workspace and add service modules

The project is now structured as a Go workspace, enabling local development and testing of multiple modules including gateway-service, user-service, task-service, logger, utils, and task-application-proto. Each service and shared module now has its own go.mod and go.sum files, establishing clear dependency boundaries and allowing independent versioning of internal packages like the shared logger and proto definitions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 54 (-4.1)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 98 (-0.9)
  • Architecture 100 → 74 (-25.9)
  • Maturity 41 → 41 (+0.0)
  • Readiness 50 → 49 (-1.1)
  • Security 89 → 77 (-11.4)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (12)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (user-service/internal/adapters/right/repo/user/sqlite/user.go)
  • Duplicated block (11 lines × 2) (user-service/internal/adapters/right/repo/user/sqlite/user.go)
  • Duplicated block (14 lines × 2) (user-service/internal/adapters/right/repo/user/repotest/user.go)
  • Duplicated block (9 lines × 2) (task-service/cmd/rest-api/main.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • single-maintainer — knowledge-concentration (bus factor) risk

New (69)

  • Critical CVE: [GHSA redacted] (task-service/go.mod)
  • Critical CVE: [GHSA redacted] (user-service/go.mod)
  • Critical CVE: [GHSA redacted] (gateway-service/go.mod)
  • Dependency pinned to a stale untagged commit: github.com/samverrall/go-task-application/logger
  • Dependency pinned to a stale untagged commit: github.com/samverrall/go-task-application/task-application-proto
  • Dependency pinned to a stale untagged commit: github.com/samverrall/go-task-application/utils
  • Dependency pinned to a stale untagged commit: golang.org/x/crypto
  • Dependency pinned to a stale untagged commit: google.golang.org/genproto
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no project overview (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (user-service/internal/adapters/right/repo/user/repotest/user.go)
  • Duplicated block (10 lines × 2) (user-service/internal/adapters/right/repo/user/repotest/user.go)
  • Duplicated block (11 lines × 2) (user-service/internal/adapters/right/repo/user/sqlite/user.go)
  • Duplicated block (11 lines × 2) (user-service/internal/adapters/right/repo/user/sqlite/user.go)
  • Duplicated block (19 lines × 2) (user-service/internal/adapters/right/repo/user/repotest/user.go)
  • Duplicated block (40 lines × 2) (task-service/internal/adapters/right/repo/task/sqlite/task.go)
  • Duplicated block (7 lines × 2) (user-service/internal/adapters/right/repo/user/sqlite/user.go)
  • Duplicated block (7 lines × 2) (user-service/internal/adapters/right/repo/user/sqlite/util.go)
  • Duplicated block (8 lines × 2) (task-service/cmd/rest-api/main.go)
  • …and 49 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

samverrall/go-task-application was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4e6b079f5c7e93c384e1eadfc5206cc9f5e42473 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.