spy16/droplets
52.6
Adequate · 21 September 2026
1.6k
lines of production code
Go
primary language
4
measurements over time
What this system is
Features
Add authentication middleware and refactor logging
The \pkg/middlewares\ package now includes a new \authn.go\ file that provides a \WithBasicAuth\ middleware for verifying user credentials and injecting the authenticated user into the request context. Additionally, the \logging.go\ file has been refactored to use a new \wrap\ helper that attaches a logger to the response writer, and the import path for the logger package has been updated from \github.com/spy16/droplet\ to \github.com/spy16/droplets\ across all files.
pkg/middlewares · high confidence
Added JSON rendering utility
The pkg/render package now includes a new JSON rendering utility that encodes Go values to JSON and writes them to an io.Writer. When the writer implements http.ResponseWriter, the function automatically sets the Content-Type header to application/json with UTF-8 charset and writes the HTTP status code, providing a convenient way to render JSON responses in HTTP handlers.
pkg/render · high confidence
Added MongoDB and REST API interfaces for posts and users
Introduced new interface implementations for the application's data and API layers. The MongoDB package (interfaces/mongo) provides persistence logic for posts and users, including connection handling and CRUD operations. The REST package (interfaces/rest) exposes these capabilities via HTTP endpoints for managing posts and users, while the web package (interfaces/web) serves the frontend application and static assets.
interfaces · high confidence
Added basic Bootstrap layout and index template for the web interface
The web layer now includes a basic Bootstrap 4.1.3 layout with an index template (index.tpl) that renders the main page structure, including a navigation bar with a search form and a welcome heading. A static CSS file (main.css) and favicon handling have also been added to support the frontend assets.
web · medium confidence
Introduced structured usecases for posts and users
The application now exposes dedicated usecase packages for managing posts and users. The posts package provides capabilities to publish, delete, and retrieve posts, including validation and conflict checking. The users package offers user registration with secret hashing, as well as retrieval and verification of user credentials. These changes restructure the internal logic into clear, package-qualified interfaces for persistence and verification.
usecases/posts, usecases/users · high confidence
Removals
Removal of the Droplet command-line entry point
The main entry point for the Droplet application, located at cmd/droplet/main.go, has been removed. This file previously initialized the logger, configured the REST API server to listen on port 8080, and started the HTTP server. Its removal indicates that the standalone Droplet service is no longer part of the codebase.
cmd · high confidence
Behavioural changes
Configurable graceful shutdown timeout
The graceful shutdown mechanism now supports a configurable timeout. The \NewServer\ function accepts a \time.Duration\ parameter to define how long the server waits for active connections to close during shutdown. This replaces the previous behavior where the shutdown used a context with no timeout, allowing administrators to control the maximum duration for graceful termination.
pkg/graceful · high confidence
Error types now include HTTP status codes
All error constructors in the errors package now populate a new 'Code' field with the corresponding HTTP status code (e.g., 400, 401, 404, 409, 500). This allows clients to easily identify the HTTP response status associated with each error type, improving integration with HTTP-based APIs.
pkg/errors · high confidence
Logger interface extended with fatal logging and simplified internal structure
The Logger interface now includes a Fatalf method, allowing callers to log fatal-level messages. Internally, the logrusLogger struct was refactored to embed \*logrus.Entry directly rather than holding it as a named field, and the explicit Debugf, Infof, Warnf, and Errorf method implementations were removed in favor of the embedded struct's methods.
pkg/logger · high confidence
Project renamed to Droplets with updated build and deployment configuration
The project has been renamed from 'droplet' to 'droplets' across the codebase, including the Go binary name, Docker image references, and Docker Compose service names. The Makefile has been updated to build the 'droplets' binary and run tests across all packages. Dockerfile and docker-compose.yml have been adjusted to reflect the new naming convention, and the docker-compose configuration now includes a MongoDB service linked to the application container.
(repo-wide) · high confidence
Removed legacy REST delivery and domain models
The internal REST delivery layer (rest.go, utils.go) and the Author domain model (author.go) have been removed from the codebase. This eliminates the previous implementation of the REST API server, JSON response helpers, and the Author struct with its email validation logic.
internal · high confidence
Restructured domain package and introduced Post and User domain models
The domain package was restructured to move types from the internal directory to the public domain package. This change introduces new domain models: Post, which represents articles, links, or videos with validation for type, body, and owner; and User, which handles user registration with email validation and password hashing via bcrypt. The existing Meta type was also updated to replace the Kind and Labels fields with Name and Tags, respectively, and the import path was updated from github.com/spy16/droplet to github.com/spy16/droplets.
domain · high confidence
Dependencies
Updated Go dependencies and module configuration
The project's Go module file (go.mod) was updated to include several new dependencies, including the Viper configuration library, the unrolled/render package, and various supporting libraries from the spf13 and BurntSushi organizations. The go.mod file was also updated to specify Go version 1.15, and the module path was changed from github.com/spy16/droplet to github.com/spy16/droplets. Corresponding checksums were added to the go.sum file.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 51 → 53 (+1.7)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (-0.4)
- Architecture 100 → 98 (-2.5)
- Maturity 47 → 47 (+0.0)
- Readiness 26 → 33 (+7.5)
- Security 98 → 87 (-11.1)
Resolved (6)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- No exposed public API
- OSV Dependency Vulnerabilities not included (check did not complete)
- Test reliability not included
- dormant codebase — no living knowledge left to concentrate
New (27)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.sum)
- Dependency pinned to a stale untagged commit: github.com/unrolled/render
- Dependency pinned to a stale untagged commit: golang.org/x/crypto
- Dependency pinned to a stale untagged commit: gopkg.in/mgo.v2
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (interfaces/mongo/posts.go)
- Duplicated block (9 lines × 2) (interfaces/mongo/posts.go)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.sum)
- High CVE: [GHSA redacted] (go.sum)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (go.sum)
- Medium CVE: [GHSA redacted] (go.sum)
- Medium CVE: GO-2021-0263 (go.mod)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium: security finding (details withheld)
- …and 7 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
spy16/droplets was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b94dee34e8528f2a1a9a01ac29b66f3c70fa8e5d — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.