Skip to content
CAI
Software that uses CAICheck a score

spf13/cobra

64.3

Adequate · 24 September 2026

6k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a command-line interface library that enhances user interaction through dynamic shell completions and automated documentation generation. It provides tools to display context-sensitive help messages during shell completion and supports generating command documentation in multiple formats, including Markdown, man pages, and YAML. The system relies on standard Go dependencies to manage flags and parse input.

Features

Introduce ActiveHelp support for shell completions

Users can now display dynamic, context-sensitive help messages during shell completion. The library adds an \active\_help.go\ module that provides \AppendActiveHelp\ and \GetActiveHelpConfig\ functions, allowing completion scripts to inject special \\activeHelp\\ prefixed strings into the completion output. This enables tools to show helpful hints or instructions to the user as they type, controlled via environment variables like \\*\_ACTIVE\_HELP\. The change also includes corresponding tests in \active\_help\_test.go\ to verify this new behavior.

(repo-wide) · high confidence

New doc package for generating command documentation in multiple formats

The \doc\ package now provides functions to generate command documentation in Markdown, man page, ReST, and YAML formats. Users can use \GenMarkdown\, \GenMan\, \GenReST\, and \GenYaml\ to produce structured documentation for their Cobra commands, with support for custom link handlers and file preprenders. The package includes comprehensive tests for each format and utility functions for sorting and formatting.

doc · high confidence

Dependencies

Updated Go dependencies and build configuration

The project's Go module dependencies have been updated to specific versions: go-md2man v2.0.6, mousetrap v1.1.0, pflag v1.0.9, and yaml v3.0.4. The Go version requirement has been set to 1.15.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 66 → 64 (-1.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 80 → 87 (+6.7)
  • Architecture 100 → 100 (+0.0)
  • Maturity 42 → 41 (-0.7)
  • Readiness 91 → 80 (-11.4)
  • Security 92 → 90 (-2.6)

Resolved (12)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (command.go)
  • Duplicated block (11 lines × 3) (doc/yaml_docs.go)
  • Duplicated block (12 lines × 3) (doc/man_docs.go)
  • Duplicated block (14 lines × 2) (doc/md_docs.go)
  • Duplicated block (6 lines × 2) (cobra.go)
  • Duplicated block (7 lines × 2) (command.go)
  • Medium CVE: GO-2021-0263 (go.mod)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included

New (37)

  • ClassTooLong: Command (command.go)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (cobra.go)
  • Duplicated block (10 lines × 3) (doc/md_docs.go)
  • Duplicated block (12 lines × 2) (command.go)
  • Duplicated block (12–14 lines × 3) (doc/man_docs.go)
  • Duplicated block (5 lines × 2) (doc/md_docs.go)
  • Duplicated block (6 lines × 2) (command.go)
  • Duplicated block (6 lines × 4) (bash_completionsV2.go)
  • Duplicated block (9 lines × 2) (bash_completionsV2.go)
  • FixmeComment (cobra.go)
  • FixmeComment (cobra.go)
  • FixmeComment (cobra.go)
  • FixmeComment (command_test.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 17 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

spf13/cobra was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit adbc8813901bba65827259daa8e22ff94ec1f30e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.