Skip to content
CAI
Software that uses CAICheck a score

Tim-Maes/GraphR

56.6

Weak · 21 September 2026

701

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

GraphR is a .NET-based application built on Clean Architecture principles, utilizing GraphQL (HotChocolate) for its API layer. It provides read and write capabilities for managing books and authors, with data access implemented via Dapper and SQL Server. The system supports database transactions and includes seed data for development.

Features

Add book query handlers for ID and author lookups

Two new query handlers have been introduced to support retrieving book data: one for fetching a single book by its ID and another for retrieving all books associated with a specific author. These handlers implement validation rules and map repository results to output DTOs, enabling these specific read operations within the application layer.

src/GraphR.Application/Books/Handlers/Query · high confidence

Added author and book query/mutation endpoints

Users can now retrieve author details and lists via new GraphQL queries, and create new books through a mutation. The change introduces the Authors and Books application layers, including query handlers for fetching authors and books, a mutation handler for creating books, and associated DTOs and mappings. Additionally, domain interfaces for author and book repositories and a transaction interface were added to support these operations.

src/GraphR.Application · high confidence

Enable GraphQL mutations and rename core handler abstractions

The API now supports GraphQL mutations in addition to queries, allowing clients to modify data (e.g., create or update records) alongside read operations. Internally, the project has been rebranded from 'CleanArchitectureTemplate' to 'GraphR', and the core handler classes have been renamed from 'QueryHandler' to 'Handler' to better reflect their role in processing both queries and mutations.

src/GraphR.API · high confidence

Introduced repository implementations and mapping configurations for Authors and Books

Added new repository classes (BookRepository, AuthorRepository) and their corresponding Dapper FluentMap mappings (BookMap, AuthorMap) to handle data access for the Book and Author entities. The BookRepository now supports retrieving books by ID or author, and creating new book records, while the AuthorRepository provides methods to fetch all authors or a specific author by ID. These changes establish the underlying data access layer for the GraphR infrastructure.

src/GraphR.Infrastructure/Repositories · high confidence

Behavioural changes

Added database transaction support and expanded seed data

The database infrastructure now supports explicit database transactions via a new DbTransaction class that manages connection and transaction lifecycles, enabling commit and rollback operations. Additionally, the database seed script has been updated to include more sample book records, increasing the initial dataset for testing and development.

src/GraphR.Infrastructure/Database · medium confidence

Infrastructure layer refactored and Dapper integration added

The infrastructure layer has been refactored, moving configuration and service registration from the old 'CleanArchitectureTemplate' namespace to the new 'GrapR' namespace. Additionally, the service collection now registers Dapper fluent mappings via the new 'AddDapperFluentMappingsInAssembly' method, enabling Dapper's type mapping features for the application.

src/GraphR.Infrastructure · medium confidence

Removal of GraphQL query and handler for retrieving a book by ID

The GraphQL query class \Query\ in \CleanArchitectureTemplate.API\ and the corresponding \GetBookByIdHandler\ in \CleanArchitectureTemplate.Application\ have been removed. This eliminates the ability to fetch a single book by its ID through the GraphQL API. Additionally, the \ServiceCollectionExtensions\ in \CleanArchitectureTemplate.Core\ has been deleted, removing the \AddCore\ registration method.

src/CleanArchitectureTemplate.API, src/CleanArchitectureTemplate.Application, src/CleanArchitectureTemplate.Core · high confidence

Removed obsolete IBookRepository interface

The IBookRepository interface, which previously defined a method for retrieving a Book by ID, has been removed from the domain layer. This change eliminates the associated interface definition, indicating a shift in how book data access is handled within the application.

src/CleanArchitectureTemplate.Domain · high confidence

Renamed solution and projects from CleanArchitectureTemplate to GraphR

The solution and all constituent projects (API, Application, Domain, Infrastructure, and Core) have been renamed from the generic 'CleanArchitectureTemplate' to 'GraphR'. This change updates the .sln file, project references, and associated metadata (such as the .nuspec file and README) to reflect the new product name, aligning the template with its specific focus on Graph API and Dapper.

(repo-wide) · high confidence

Dependencies

Upgrade HotChocolate and update .NET project references

The project references have been renamed from 'CleanArchitectureTemplate' to 'GraphR' across the solution, and the HotChocolate ASP.NET Core package has been upgraded from version 13.7.0 to 13.9.0. Additionally, the application layer now includes HotChocolate.Abstractions and HotChocolate.Types at version 13.9.0. Other dependency updates include FluentValidation (11.8.1 → 11.9.0), Bindicate (1.2.0 → 1.5.1), Dapper (2.1.21 → 2.1.28), dbup (5.0.8 → 5.0.37), and Microsoft.Data.SqlClient (5.1.2 → 5.2.0-preview4.23342.2).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 57 (-1.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 82 → 82 (+0.0)
  • Architecture 86 → 86 (+0.0)
  • Maturity 49 → 49 (+0.0)
  • Readiness 55 → 47 (-8.3)
  • Security 73 → 80 (+7.0)

Resolved (14)

  • Deprecated: Dapper.FluentMap
  • High CVE: System.Text.Json 8.0.0
  • High CVE: System.Text.Json 8.0.0
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: Microsoft.Identity.Client 4.56.0
  • Medium CVE: Azure.Identity 1.10.3
  • Medium CVE: Azure.Identity 1.10.3
  • No exposed public API
  • The 'Example' section is present in the outline but not shown, leaving the reader unable to run the template and test the API. (README.md)
  • single-maintainer — knowledge-concentration (bus factor) risk

New (18)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: System.Text.Json 8.0.0
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent generic type parameter naming across the handler interfaces and classes. Some use 'TResult' for the output type, while others use 'TOutput'. Similarly, the input type parameter is sometimes 'TInput' and sometimes implied or missing in the base interface definition. This creates confusion when implementing or consuming these interfaces, as the contract for the output type is not uniformly named.
  • Inconsistent generic type parameter naming across the handler interfaces and classes. Some use 'TResult' for the output type, while others use 'TOutput'. Similarly, the input type parameter is sometimes 'TInput' and sometimes implied or missing in the base interface definition. This creates confusion when implementing or consuming these interfaces, as the contract for the output type is not uniformly named.
  • Inconsistent method naming for the core execution logic. Some handlers use 'Handle' with parameters, while others use 'Handle' without parameters (for parameterless handlers). More critically, the generic parameter names in the interfaces ('TResult' vs 'TOutput') and the corresponding method signatures are inconsistent, making it difficult to reason about the handler contract.
  • Medium CVE: Azure.Identity 1.10.3
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Outdated: Dapper.FluentMap

Architecture

  • Unchanged — 2 containers · 0 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Tim-Maes/GraphR was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fad9b1b702687c32d527e8c8e30329d80391e853 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.