Skip to content
CAI
Software that uses CAICheck a score

vindecodex/msgo

56.6

Adequate · 21 September 2026

822

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added DTOs for book and user request/response models

New data transfer objects have been introduced in the dto package, including BookRequest, BookResponse, UserRequest, and UserAuthRequest. Each request DTO includes a Validate method that enforces non-empty fields, returning an UnprocessableEntity error if validation fails. Corresponding unit tests verify the validation logic for these models.

dto · medium confidence

Added Viper-based configuration loading with sample templates

The application now uses the Viper library to load configuration from a 'conf' file in the './config' directory, with environment variable overrides enabled. A new 'config' package provides a 'GETSTRING' helper to retrieve configuration values. To assist with setup, sample configuration templates in both TOML and YAML formats have been added, defining default values for database credentials (DB\_USER, DB\_PWD, DB\_HOST, DB\_NAME) and application settings (PORT, ENVIRONMENT).

config · medium confidence

Added authentication middleware

Introduced a new authentication middleware that validates user access by checking for a Bearer token in the Authorization header. The middleware allows public access to /login and /register, while requiring valid tokens for other endpoints, returning 401 Unauthorized for missing or invalid credentials.

middleware · high confidence

Added book and user service implementations

Introduced the BookService interface and its DefaultBookService implementation, providing methods to create, read, update, and delete books via a repository layer. Added the UserService interface and its DefaultUserService implementation, handling user registration and login with token generation. Included corresponding unit tests for the book service and a readme explaining the mock generation process.

service · high confidence

Added initial controller layer for books, users, and welcome endpoints

Introduced the application's HTTP controller layer, providing handlers for book management (GetAllBooks, GetBook, NewBook, UpdateBook, DeleteBook), user authentication (Login, Register), and a root welcome message. The implementation includes a shared writeResponse utility for JSON serialization and integrates with the service layer to handle request parsing, validation, and error reporting.

controller · high confidence

Initial domain layer for books and users

The application now includes the core domain models and repository adapters for managing books and users. The Book model and its SQL-based repository adapter provide full CRUD operations (GetAll, GetById, Save, Update, Delete) and response mapping. The User model includes JWT-based token generation and verification, along with role-based authorization logic that maps user roles to permitted URL paths. These changes establish the foundational data access and business logic for the system.

domain · high confidence

Initial release of MSGO: a Go microservices application with Docker support

The repository introduces MSGO, a Go-based application implementing a hexagonal architecture with MySQL database initialization and a REST API for managing books and users. The release includes a Dockerfile, a docker-compose.yml for running the application and a MySQL 5.7 database container on port 3003, and a db\_init.go script that creates the 'msgo' database and 'books' and 'users' tables. The main.go file sets up the HTTP router using gorilla/mux and registers controllers for books and users, along with an authentication middleware. The project also includes a README with setup instructions and an MIT license.

(repo-wide) · high confidence

Introduction of structured error types for HTTP status codes

A new \errs\ package has been added, introducing a structured \Error\ type that wraps HTTP status codes and messages. This provides a consistent way to represent common HTTP errors such as 404 Not Found, 500 Internal Server Error, and 401 Unauthorized, each with a dedicated constructor function.

errs · high confidence

Behavioural changes

Add structured logging with Zap

The application now uses the Zap library for structured logging. A new logger package initializes a production-configured logger that outputs ISO8601 timestamps and omits stack traces. The logger exposes Info and Error methods to log messages at the respective levels.

logger · high confidence

Dependencies

Initial Go module and dependency configuration

The project now includes a go.mod file defining the module github.com/vindecodex/msgo with Go 1.13 and a set of direct dependencies including github.com/gbrlsnchs/jwt/v3, github.com/go-sql-driver/mysql, github.com/golang/mock, github.com/gorilla/mux, github.com/jmoiron/sqlx, github.com/spf13/viper, and go.uber.org/zap, along with their indirect dependencies. A corresponding go.sum file is added to lock the specific versions of all transitive dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 52 → 57 (+5.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.3)
  • Architecture 69 → 69 (+0.0)
  • Maturity 63 → 63 (+0.0)
  • Readiness 26 → 38 (+12.1)
  • Security 97 → 89 (-8.0)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (7)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness

New (19)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.sum)
  • Duplicated block (9 lines × 2) (controller/writeResponse.go)
  • High CVE: [GHSA redacted] (go.sum)
  • Medium CVE: [GHSA redacted] (go.sum)
  • Medium CVE: [GHSA redacted] (go.sum)
  • Medium CVE: GO-2021-0226 (go.mod)
  • Medium CVE: GO-2026-6179 (go.sum)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • No ADRs found
  • Outdated: github.com/gbrlsnchs/jwt/v3
  • Outdated: github.com/go-sql-driver/mysql
  • Outdated: github.com/gorilla/mux
  • Outdated: github.com/jmoiron/sqlx
  • Outdated: github.com/spf13/viper
  • Outdated: go.uber.org/zap
  • Scattered collaborators

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

vindecodex/msgo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 991c83127c2b72a00bff33c5de9d04d52c5a3522 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.