Skip to content
CAI
Software that uses CAICheck a score

sklinkert/go-ddd

78.7

Strong · 21 September 2026

2.1k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based marketplace service that manages products and sellers through a REST API. It implements a Domain-Driven Design architecture with CQRS patterns, utilizing sqlc for type-safe PostgreSQL access and enforcing strict data validation. The service ensures reliability through idempotent request handling, soft deletes, and a transactional outbox pattern for domain event publishing.

How it got here

2023 — Domain-Driven Go scaffolding and API implementation

12 changes.

The project established a production-ready template for Domain-Driven Go services, introducing sqlc for type-safe PostgreSQL access, Docker-based infrastructure, and comprehensive tooling. It implemented a REST API for products and sellers with strict idempotency, CQRS patterns, and a transactional outbox for domain events. The work focused on building a robust, testable foundation with validated domain entities and structured logging.

2024–2025 — Marketplace domain and API layer implementation

7 changes.

This period focused on establishing the core marketplace domain by implementing SQL-based migrations, data access layers, and reliability patterns such as idempotency and outbox queues. It also involved building the REST API interface through dedicated request and response DTOs, ensuring a clean separation between internal domain entities and external contracts.

Features

Domain entities with validation, idempotency, and domain events

The domain layer now enforces strict invariants through validated aggregates: Product and Seller entities require explicit validation (e.g., non-empty names, positive prices, valid seller references) and expose UpdateName/UpdatePrice methods that update timestamps and re-validate. A new Money value object stores amounts in ISO 4217 minor units to prevent floating-point errors, with exponent-aware formatting for currencies like JPY. Idempotency records track request/response states to support safe retries, while domain events (e.g., ProductCreated) are recorded on aggregates and pulled for transactional outbox persistence.

internal/domain/entities · high confidence

Introduce DTO mappers for Product and Seller responses

New mapper functions have been added to convert internal domain results into REST API response DTOs for Products and Sellers. This ensures that domain entities are not exposed directly to the outside world, providing a clean separation between the internal application layer and the API contract. The mappers handle the transformation of IDs, names, timestamps, and monetary values (including minor units and currency) into the specific JSON structures expected by API consumers.

internal/interface/api/rest/dto/mapper · high confidence

Introduce application service interfaces for product and seller operations

New interface definitions for ProductService and SellerService have been added to the application layer. These interfaces standardize how the application handles core business operations, exposing methods for creating, updating, deleting, and querying (FindAll, FindById) both products and sellers. This change establishes a contract for command and query execution, separating the application logic from the underlying implementation details.

internal/application/interfaces · high confidence

Introduce production scaffolding: Go 1.26, sqlc, Docker, and migration tooling

The repository now provides a complete, runnable template for building Domain-Driven Go services. It upgrades the target to Go 1.26 and replaces the previous ORM with sqlc for type-safe PostgreSQL access using pgx/v5. A new Dockerfile and docker-compose.yml allow starting the application and a Postgres 17 database with a single command, while a built-in migrate.go utility and Makefile targets manage SQL schema migrations. The project also includes a MkDocs-based tutorial site, a .golangci.yml configuration enforcing specific style conventions (like the \Id\ naming pattern), and a Makefile that standardizes building, linting, testing (including Docker-based integration tests via testcontainers), and vulnerability scanning.

(repo-wide) · high confidence

Introduce request DTOs with idempotency support for product and seller operations

Added new REST request DTOs (CreateProductRequest, UpdateProductRequest, CreateSellerRequest, UpdateSellerRequest) in the internal API layer that map JSON payloads to application commands. These DTOs introduce an idempotency\_key field to support race-safe, idempotent operations and use price\_minor\_units for currency amounts. The product update DTO derives the product ID from the URL path rather than the request body, while seller updates include the ID in the payload. Comprehensive tests verify JSON tag mapping, command conversion, and invalid seller ID handling.

internal/interface/api/rest/dto/request · high confidence

New repository interfaces for products, sellers, and idempotency

The application now exposes explicit repository interfaces for managing products, sellers, and idempotency records. Product and Seller repositories define standard CRUD operations (Create, FindById, FindAll, Update, Delete) using UUIDs and validated entity types, while the new IdempotencyRepository provides methods to atomically reserve, find, set responses for, and delete idempotency keys to support race-safe operations.

internal/domain/repositories · high confidence

REST API for Products and Sellers with Idempotency and Health Checks

The REST interface now exposes full CRUD operations for products and sellers under the /api/v1 prefix, including endpoints for creating, retrieving, updating, and deleting resources. The API enforces idempotency for mutating requests (POST, PUT, DELETE) by honoring the Idempotency-Key header or body field, ensuring safe retries. It also provides /healthz and /readyz endpoints for liveness and readiness probes, with readiness checking database connectivity. Error handling maps domain errors to appropriate HTTP status codes (404, 400, 409, 422) instead of generic 500s.

internal/interface/api/rest · high confidence

SQL query definitions for marketplace domain entities and reliability patterns

This change introduces the SQL query definitions for the marketplace's core domain entities (products, sellers) and reliability mechanisms (idempotency, outbox). For users, this establishes the data access layer for managing product and seller lifecycles, including soft-delete support where records are marked with a deletion timestamp rather than physically removed. It also adds support for race-safe idempotency keys to prevent duplicate request processing and an outbox pattern for reliable event publishing, ensuring that domain events are persisted before being sent to downstream consumers.

sql · high confidence

Behavioural changes

Add mappers to expose domain entities as DTOs

New mapper functions have been added for Product and Seller to convert domain entities into common result DTOs. This ensures that internal domain models are not exposed directly to the outside world, providing a clean boundary for API responses.

internal/application/mapper · high confidence

Application services now enforce idempotency and structured query results

Product and seller operations (create, update, delete) are now wrapped in an idempotency layer that prevents duplicate execution for the same key, handles concurrent requests, and replays cached results. Query operations now return dedicated result types (e.g., GetAllProductsQueryResult, GetProductByIdQueryResult) instead of raw domain entities, ensuring consistent, decoupled responses for consumers.

internal/application/services · high confidence

Database layer migrated to sqlc with transactional outbox and idempotency support

The internal database infrastructure has been rewritten to use sqlc for type-safe SQL generation, replacing the previous ORM. This change introduces a transactional outbox pattern for domain events, ensuring that product creation and event publishing are committed atomically, and adds a race-safe idempotency repository to prevent duplicate request processing. Additionally, the system now supports soft deletes for products and sellers, and prices are stored and exposed using minor units (e.g., cents) for currency precision.

internal/infrastructure · high confidence

Initial database schema and migration strategy for marketplace domain

The application now uses a SQL-based migration system to manage the database schema, replacing the previous ORM approach. The initial schema introduces tables for sellers and products, including support for soft deletes via a \deleted\_at\ column. Product pricing is stored as integer minor units (\price\_minor\_units\) alongside an ISO 4217 currency code to ensure precision, with a migration handling the conversion from previous decimal formats. Additionally, the schema includes tables for idempotency records to prevent duplicate processing and an outbox table to guarantee reliable delivery of domain events to message brokers.

migrations · high confidence

Introduce CQRS command structures for product and seller management

The application layer now exposes explicit command and result types for creating, updating, and deleting products and sellers. Each command includes an idempotency key to support race-safe idempotent operations, and product commands carry price details (minor units and currency) alongside seller references. This change establishes the input contracts for the command handlers that process these domain actions.

internal/application/command · high confidence

Introduce product and seller result DTOs to decouple domain entities from external interfaces

New result structs (ProductResult, SellerResult) have been added to the common application layer to serve as data transfer objects. These structs explicitly define the fields exposed to external consumers (such as IDs, names, prices, and timestamps), ensuring that internal domain entities are not directly exposed. This change supports the controller-level refactoring that maps domain data to these specific output shapes, providing a stable contract for API responses.

internal/application/common · high confidence

Introduce response DTOs for products and sellers with timestamp fields

New response Data Transfer Objects (ProductResponse, ListProductsResponse, SellerResponse, ListSellersResponse) have been added to the REST API layer. These DTOs define the external JSON structure for product and seller data, explicitly including CreatedAt and UpdatedAt timestamp fields. This change ensures that domain entities are not exposed directly to the outside world, providing a stable contract for API consumers.

internal/interface/api/rest/dto/response · high confidence

Marketplace server entry point with graceful shutdown and structured logging

The application now includes a main entry point that initializes the HTTP server using the Echo framework, connects to PostgreSQL via sqlc, and wires up product, seller, and health controllers. It implements graceful shutdown handling for SIGINT/SIGTERM signals, ensuring in-flight requests are drained before exit, and exits with a non-zero status if the server fails to start. Additionally, it integrates an outbox relay for publishing domain events and uses structured logging (slog) to record request details such as method, URI, status, latency, and request ID.

cmd · high confidence

Test coverage

Added REST controller tests for products and sellers

Added comprehensive integration tests for the REST API controllers in the \rest\_test\ package. This includes mock implementations for \ProductService\ and \SellerService\ to isolate controller logic, along with test cases covering CRUD operations (create, read, update, delete) and edge cases such as invalid IDs, not-found scenarios, and service errors for both product and seller endpoints.

_internal/interface/api/rest\test · high confidence

Dependencies

Update Go dependencies and vendor testcontainers-go documentation assets

This change updates the project's Go module dependencies, including labstack/echo/v4 to 4.15.4, testcontainers-go to 0.44.0, and golang.org/x/crypto to 0.54.0, while also vendoring the documentation requirements (Pipfile, requirements.txt) for testcontainers-go and OpenTelemetry.

(dependencies) · high confidence

Updated vendored dependencies

The vendor directory has been updated to include newer versions of several Go dependencies, including mergo, go-ansiterm, and others, reflecting the dependency bumps listed in the commit history (e.g., gorm.io/driver/sqlite, testcontainers-go, echo, pgx, migrate, grpc, crypto, otel, testify, moby/go-archive).

vendor · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 71 → 79 (+7.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 98 (+1.4)
  • Architecture 100 → 80 (-20.1)
  • Maturity 76 → 84 (+7.9)
  • Readiness 73 → 87 (+14.3)
  • Security 66 → 80 (+14.3)
  • Domain Modelling 70 → 75 (+4.5)

Resolved (27)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: GO-2026-4918 (go.mod)
  • Medium CVE: GO-2026-5158 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: CKV_DOCKER_2 (Dockerfile)
  • Medium IaC: CKV_OPENAPI_21 (api/openapi.yaml)
  • Medium IaC: CKV_OPENAPI_5 (api/openapi.yaml)
  • …and 7 more

New (26)

  • ADR not followed: 7. Domain events and the outbox (docs/tutorial/07-domain-events-outbox.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (docs/tutorial/09-testing.md)
  • Duplicated block (10 lines × 2) (internal/domain/entities/validated_product.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • …and 6 more

Changes since last survey

  • 7 commits — 6 feature/other, 1 fixes

By area

  • vendor/github.com — 3 commits
  • (root) — 2 commits
  • vendor/go.yaml.in — 1 commit
  • vendor/golang.org — 1 commit

Notable commits

  • fix: Go security: Move CI to Go 1.26.6 so stdlib CVE fixes actually land (#97)
  • change: Bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#96)
  • change: Bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#98)
  • change: Bump github.com/testcontainers/testcontainers-go from 0.43.0 to 0.44.0 (#94)
  • change: Bump github.com/testcontainers/testcontainers-go/modules/postgres (#93)
  • change: Go security: Block vulnerable dependencies before merge (#92)
  • change: Go security: Bump moby/go-archive to v0.3.0 to close tar path traversal (#100)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sklinkert/go-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 64574f4e84e77baaa033c30c44bd9fff893f90fc — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.