Skip to content
CAI
Software that uses CAICheck a score

SamWarden/user_service

56.2

Weak · 22 September 2026

2.3k

lines of production code

Python

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Python-based user management service built on a clean architecture with domain-driven design principles. It provides APIs for creating, updating, and retrieving user profiles, managing database interactions via SQLAlchemy, and handling asynchronous messaging through RabbitMQ. The service is containerized for local and production deployment, with comprehensive test coverage for both unit and integration scenarios.

Features

Introduce domain layer for user management

The user service domain now includes a complete domain layer, introducing a \UserService\ that handles creating, updating, and deleting users, along with associated domain events (e.g., \UserCreated\, \UsernameUpdated\). This change adds value objects for user data (such as \Username\, \FullName\, and \UserId\), a \User\ entity, and a \UserRepo\ interface, establishing the foundation for user-related business logic and event tracking.

_src/user\service/domain · medium confidence

Introduce structured dependency injection and mediator configuration

The user service now organizes its core infrastructure into a dedicated \main\ package, separating the dependency injection (DI) container setup from the mediator (command/query/event) configuration. The DI layer, located in \src/user\_service/main/di/\, now explicitly defines scopes (APP, REQUEST) and registers factories for the database session, message broker channels, and the unit of work. The mediator layer, in \src/user\_service/main/mediator/\, initializes the command, query, and event dispatchers, and registers all application handlers (e.g., CreateUser, GetUserById) with the mediator. This refactoring provides a clear, centralized entry point for initializing the service's internal architecture.

_src/user\service/main · high confidence

Introduces domain-driven application layer and infrastructure for user management

The user service now implements a structured application layer with command and query handlers for creating, updating, and deleting users, alongside query handlers for retrieving user data. This is supported by new infrastructure components including a SQLAlchemy-based database layer with Alembic migrations, a unit of work for transaction management, and an event bus for publishing integration events. Users can now have their full name and username updated, and the system enforces unique usernames and handles soft deletes via a new \deleted\_at\ column.

_src/user\service/infrastructure · high confidence

Project scaffolding and infrastructure configuration

The project is initialized with essential configuration files and infrastructure definitions. This includes a Dockerfile for containerization, a docker-compose.yaml defining services for the API, Postgres, RabbitMQ, and a Grafana monitoring stack. Development tooling is configured via .pre-commit-config.yaml (using ruff, mypy, and hadolint), a justfile for build/run commands, and pyproject.toml/uv.lock for dependency management. Additionally, the repository includes a README.md, LICENSE.md, and environment templates to support local development and deployment.

(repo-wide) · high confidence

Behavioural changes

Removed version constant from package initialization

The \_\init\\.py file in the src directory has been deleted, removing the \\version\\_ constant that previously exposed the package version as '0.1.0'.

src · high confidence

Restructured user\_service into src-layout with new entry point

The user\service package has been reorganized into a src-layout, introducing a new \\init\\.py to define the package version and a new \\main\\_.py to serve as the application's entry point. This file establishes the startup sequence, configuring logging, database connections, message brokers, and dependency injection containers before initializing the API server.

_src/user\service · high confidence

Test coverage

Add integration tests for Alembic migration stairway; Added Postgres test fixtures and removed obsolete version test; Added unit tests for user management command and query handlers.

Dependencies

Migrate from Poetry to Setuptools and update project metadata

The project has switched its build system from Poetry to Setuptools, removing the \poetry.lock\ file and updating \pyproject.toml\ to use \setuptools\ as the build backend. The project name was changed from \pytemplate\ to \user\_service\, the required Python version was raised to 3.13, and the dependency list was updated to include packages such as \adaptix\, \aio-pika\, \fastapi\, and \uvicorn\. Additionally, development, testing, and linting dependencies were reorganized into separate groups, and the project's homepage and repository URLs were updated.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 62 → 56 (-6.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.2)
  • Architecture 100 → 74 (-25.9)
  • Maturity 53 → 53 (-0.4)
  • Readiness 49 → 41 (-7.4)
  • Security 86 → 87 (+1.1)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (20)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (uv.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: PYSEC-2026-2132 (uv.lock)
  • Medium CVE: PYSEC-2026-2987 (uv.lock)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • The README states Clean Architecture with DDD tactical patterns and CQRS but never explains what each pattern/feature in the API corresponds to or how it is implemented. (README.md)

New (36)

  • Critical CVE: [GHSA redacted] (uv.lock)
  • Critical CVE: [GHSA redacted] (uv.lock)
  • Documentation: no architecture or design documentation (README.md)
  • Duplicated block (6 lines × 2) (src/user_service/application/user/queries/get_user_by_id.py)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High IaC: WD-COMPOSE-0001 (docker-compose.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0026 (Dockerfile)
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: [GHSA redacted] (uv.lock)
  • …and 16 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

SamWarden/user_service was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 220542f176dd92ddad183bc7b979369e006193a1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.