Skip to content
CAI
Software that uses CAICheck a score

stackus/edat

68.4

Adequate · 21 September 2026

3.7k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added mock logger and test helpers for the logging package

The log package now includes a generated mock implementation of the Logger interface in the logmocks package, enabling easier unit testing of components that depend on it. A corresponding test helper function, MockLogger, is provided in the logtest package to simplify the setup of these mocks in tests. Additionally, the core log/logger.go file was updated with clarifying comments and the addition of a DefaultLogger variable, which allows users to globally override the default no-op logger if desired.

log · high confidence

Support multiple message receivers per channel in the message subscriber

The message subscriber now allows multiple message receivers to be subscribed to the same channel, rather than a single receiver. When a message is received, it is dispatched to all registered receivers for that channel concurrently. This change enables more flexible message routing and processing patterns within the messaging system.

msg · high confidence

Behavioural changes

Added GoDoc comments to the retry package

All public types, functions, and constants in the retry package now include GoDoc comments. This improves the API documentation, making it easier for users to understand the purpose of the Backoff struct, the NewBackoff and NewExponentialBackoff constructors, and the ErrDoNotRetry error handling.

retry · high confidence

Added gRPC request context propagation

A new \context.go\ file was added to the \grpc\ package, introducing interceptors and stream wrappers that propagate request, correlation, and causation IDs through gRPC metadata headers. This enables consistent request tracking across gRPC server and client boundaries.

grpc · high confidence

Fix in-memory event store out-of-bounds error

The in-memory event store's Load method now correctly includes the current version in the range of events to load, preventing an out-of-bounds error that occurred when the stream length matched the expected version. Additionally, the store now returns a specific \es.ErrAggregateVersionMismatch\ error for optimistic concurrency conflicts instead of a generic error message.

inmem · high confidence

HTTP middleware now propagates request IDs to response headers

The HTTP layer now automatically injects the request, correlation, and causation IDs into the outgoing HTTP response headers. Previously, these IDs were only set in the request context; now, the \SetResponseHeaders\ function (renamed from \SetRequestHeaders\) ensures that clients receive these identifiers in the response, improving traceability and debugging capabilities for API consumers.

http · high confidence

Improved error handling and state management for Event Sourcing aggregates

The Event Sourcing module now enforces stricter state management and provides clearer error signals. A new ErrPendingChanges error is returned when attempting to process a command while previous changes are still pending, preventing invalid command application. Additionally, the repository layer now explicitly returns ErrAggregateNotFound when attempting to update a non-existent aggregate, and ErrAggregateVersionMismatch is defined for handling version conflicts during event appending. These changes improve the developer experience by making aggregate lifecycle errors explicit and easier to handle.

es · high confidence

Refactor outbox message processing into a separate method

The outbox polling processor's message processing logic has been extracted from the main loop into a dedicated \processMessage\ method. This change improves code organization and readability by isolating the steps for transforming stored messages into outbound messages and publishing them, while preserving the existing error handling and logging behavior.

outbox · high confidence

Refactor saga message header parsing and add command dispatcher tests

The saga package refactors how message headers are parsed by extracting header extraction logic into dedicated helper methods (commandMessageInfo and replyMessageInfo) in the CommandDispatcher and Orchestrator, reducing code duplication and improving error handling. Additionally, comprehensive unit tests have been added for the CommandDispatcher to verify message handling for success, handler errors, unregistered commands, and missing headers.

saga · medium confidence

Test coverage

Add core test helpers and mocks for command, event, and reply serialization; Added mock implementations for message bus interfaces; Added msgtest package with mock helpers for message testing.

Dependencies

Updated Go dependencies and toolchain

The project has been updated to use Go 1.16 and added new dependencies for gRPC (v1.38.0) and testing (testify v1.7.0), alongside various transitive dependencies in go.sum.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 67 → 68 (+1.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 98 (+0.7)
  • Architecture 100 → 95 (-4.7)
  • Maturity 55 → 55 (+0.0)
  • Readiness 68 → 66 (-1.2)
  • Security 74 → 85 (+11.3)
  • Domain Modelling 100 → 100 (-0.0)
  • Event-Driven 100 → 100 (+0.0)

Resolved (15)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (12 lines × 3) (msg/publisher.go)
  • Duplicated block (15 lines × 2) (grpc/context.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient
  • single-maintainer — knowledge-concentration (bus factor) risk

New (29)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: golang.org/x/sync
  • Documentation: no architecture or design documentation (README.md)
  • Duplicated block (10 lines × 3) (msg/publisher.go)
  • Duplicated block (19 lines × 2) (grpc/context.go)
  • HackComment (msg/subscriber_test.go)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.sum)
  • High interface indirection
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.sum)
  • Medium CVE: [GHSA redacted] (go.sum)
  • Medium CVE: GO-2022-0433 (go.mod)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 9 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

stackus/edat was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b5ff6cb363882877ac8ca487785e4536167744f8 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.