Skip to content
CAI
Software that uses CAICheck a score

sergicanet9/go-hexagonal-api

54.3

Adequate · 21 September 2026

1.2k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add MongoDB user repository with transactional batch creation

The MongoDB infrastructure layer now includes a new user repository implementation (user.go) that provides a CreateMany method for batch user creation. This method executes operations within a MongoDB transaction configured with majority write concern and snapshot read concern, ensuring data consistency during batch inserts. A corresponding test suite (user\_test.go) validates the repository creation and the CreateMany functionality, including error handling for failed operations.

infrastructure/mongo · medium confidence

Add PostgreSQL user repository and initial database schema

Introduced a new PostgreSQL-based user repository implementation, including the initial database migration script that creates the \users\ table and a corresponding Go adapter (\user.go\) that handles CRUD operations (Create, Get, GetByID, Update, Delete, CreateMany) against the database. The change also includes comprehensive unit tests (\user\_test.go\) for the repository methods, verifying successful operations, error handling, and edge cases like non-existent resources.

infrastructure/postgres · high confidence

Add async health-checker service for HTTP and gRPC endpoints

A new async package has been introduced to manage background health-checking tasks. The implementation launches HTTP and gRPC health-checker goroutines that periodically probe the respective endpoints. The health endpoints are now served under the /v1/ path. A corresponding test suite verifies the initialization and context cancellation behavior of the async runner.

app/async · high confidence

Add gRPC and gRPC-Gateway support alongside HTTP API

The API layer now supports both gRPC and HTTP/REST endpoints. The gRPC server is configured with New Relic observability, JWT authentication, and recovery middlewares. An HTTP server is introduced that proxies requests to the gRPC backend via gRPC-Gateway, exposing Swagger documentation, a gRPC-UI interface for testing, and standard HTTP routes under the /v1 prefix.

app/api · high confidence

Added HTTP and gRPC health check implementations

Introduced new healthchecker components that perform periodic health checks via HTTP and gRPC. The HTTP checker sends GET requests and logs status, while the gRPC checker connects to a service and calls a HealthCheck RPC. Both functions run in a loop until the provided context is cancelled, and they utilize the shared observability logger for all status and error reporting.

app/async/healthchecker · high confidence

Added v1 gRPC and HTTP API definitions for user and health services

The proto directory now contains the complete v1 API contract, including \health.proto\ and \user.proto\ which define the gRPC services and message types. This change also introduces the corresponding Go code generation configuration (\buf.yaml\, \buf.gen.yaml\, \buf.lock\) and the generated Go files (\health.pb.go\, \user.pb.go\, etc.) that implement the HTTP-to-gRPC gateway, enabling RESTful JSON endpoints for user management and health checks.

proto · high confidence

Added v1 gRPC handlers for health checks and user management

Introduced new gRPC handlers in the v1 API layer, including a health check endpoint that returns system status and environment details, and a comprehensive set of user management handlers (login, create, create many, get all, get by email, get by ID) with corresponding unit tests.

app/handlers/v1 · medium confidence

Introduce structured configuration management with environment-specific overrides

The application now uses a centralized configuration system that loads default settings from config.json and applies environment-specific overrides (e.g., config.local.json, config.prod.json). This allows runtime parameters like async task intervals and timeouts to be easily adjusted per environment. The change includes the Go implementation for reading and merging these JSON configuration files, along with unit tests to verify correct loading and error handling for missing or invalid configuration paths.

config · high confidence

Introduce user management capabilities with validation and authentication

The core module now includes a complete user management feature, introducing the ability to create, retrieve, update, and delete users, as well as handle user login with JWT-based authentication. The change adds the User entity, request/response models with input validation, a service layer for business logic (including password hashing and token generation), and the corresponding ports and tests.

core · high confidence

Behavioural changes

Introduce configurable database adapter selection and structured startup

The application now allows users to select the database adapter (MongoDB or PostgreSQL) via the --db flag, and requires explicit configuration of the database connection string (DSN). The main entry point has been refactored to initialize both HTTP and gRPC servers concurrently, with graceful shutdown handling and New Relic observability integration. This change enables multi-environment configurations and supports both sync and async processing modes.

cmd · medium confidence

Test coverage

Added integration tests for user and health endpoints

Added integration tests for the health check, user login, user creation, and user creation-batch endpoints, along with the corresponding mock implementations for UserRepository and UserService to support these tests.

test · high confidence

Dependencies

Updated Go dependencies and framework versions

The project's go.mod and go.sum files have been updated to use newer versions of the scv-go-tools (v4) and scv-go-framework (v1.0.0) packages, alongside updates to gRPC, MongoDB, and other Go dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 54 (-2.6)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 100 (+0.2)
  • Architecture 100 → 69 (-31.0)
  • Maturity 63 → 63 (+0.0)
  • Readiness 58 → 55 (-2.7)
  • Security 43 → 44 (+1.2)

Resolved (45)

  • Build action pinned to a mutable branch
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (12 lines × 2) (app/handlers/v1/user.go)
  • Duplicated block (13 lines × 2) (core/models/user.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 25 more

New (131)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Deprecated module: go.mongodb.org/mongo-driver
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (15 lines × 2) (app/handlers/v1/user.go)
  • Duplicated block (15 lines × 2) (core/models/user.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 111 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sergicanet9/go-hexagonal-api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7b5fe6d4c6073d4727cad1ac88c59f737259ad42 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.