wesionaryTEAM/go_clean_architecture
55.0
Adequate · 21 September 2026
2.4k
lines of production code
Go
primary language
4
measurements over time
What this system is
This is a Go-based web application that manages user accounts and enforces role-based access control. It provides a RESTful API for creating and retrieving users, backed by a MySQL database and Amazon Cognito for authentication. The system also includes CLI tools for database migrations, local development, and initial data seeding.
How it got here
2020 — Project scaffolding and legacy cleanup
6 changes.
The period focused on initializing the project infrastructure with configuration files, a Makefile, and a pre-commit hook, while simultaneously removing legacy code for posts and Firestore-based repositories. This was accompanied by updating Go dependencies and the runtime version to modernize the toolchain.
2021–2024 — Core application architecture and CLI infrastructure
7 changes.
This period focused on establishing the foundational application structure, including a new CLI interface using Cobra and fx for dependency injection. It also introduced containerized development environments for MySQL and Go services, alongside the initial database schema and user domain logic.
Features
Added Docker configuration for MySQL and Go web services
Introduced new Docker support files to enable containerized development and database management. A MySQL server image (db.Dockerfile) is now configured to use a custom character set (utf8mb4) via a new custom.cnf file. Additionally, a Go web service Dockerfile (web.Dockerfile) is added, which installs build dependencies including Delve for debugging, and utilizes a new run.sh script that manages the Go application's lifecycle with hot-reload capabilities using inotifywait.
docker · medium confidence
Added admin user seeding capability
The application now includes a mechanism to automatically seed an initial admin user. A new \AdminSeed\ component has been added to create a user with the admin role in both the local database and the Cognito service. This is wired into the application's dependency injection container via the \seeds\ package, which provides a \Seeds\ type to manage and run all available data seeds.
seeds · high confidence
Initial project scaffolding and configuration
The repository is initialized with essential configuration files, including an .editorconfig for consistent code formatting, a .gitignore to exclude sensitive files, and a .golangci.yml for Go linting rules. A Makefile is added to manage database migrations using the Atlas tool, providing commands to apply, diff, and rollback migrations. The project structure includes a main.go entry point, a docker-compose.yml for local development with MySQL and Adminer, and documentation files (README.md, CONTRIBUTING.md, SECURITY.md) to guide users on setup, testing, and contributing.
(repo-wide) · high confidence
Introduce CLI commands for serving the application and managing the database
The console package now provides a CLI interface using Cobra, allowing users to run the application via the 'app:serve' command. This command initializes the application using the fx dependency injection framework, configures the server with environment-based settings (such as timezone and Sentry error tracking), and handles startup errors gracefully. Additionally, the codebase includes commands for database management, specifically 'test:db-up' and 'test:db-down', facilitating test database setup and teardown.
console · medium confidence
Introduce CLI entry point and dependency injection container
A new bootstrap package was added to the project, establishing the application's CLI entry point using the Cobra library and configuring a dependency injection container via Uber's fx framework. The bootstrap module wires together the core application modules (pkg, domain, and seeds) to enable command-line execution and script-based dependency resolution.
bootstrap · high confidence
Introduce user domain with CRUD operations and role-based access
The domain layer now includes a complete user management feature, providing endpoints to create and retrieve users. The User model supports role-based access control (e.g., 'admin' via constants.UserRole) and integrates with Amazon Cognito for authentication. The implementation includes a controller handling HTTP requests, a service layer for business logic, and a repository for database interactions using GORM. Routes are registered under /api/user, supporting POST for creation and GET for retrieval by ID.
domain · high confidence
Behavioural changes
Added initial users table migration via Atlas
A new SQL migration file (20240606114654.sql) was added to the migrations directory, defining a 'users' table with fields for identity, name, email, and role, along with associated indexes and unique constraints. An Atlas checksum file (atlas.sum) was also added to verify the migration's integrity.
migrations · high confidence
Added pre-commit hook for Go files
A new pre-commit hook has been added to the hooks directory. This hook automatically runs goimports and golangci-lint on all staged .go files before each commit, ensuring code formatting and linting standards are met.
hooks · medium confidence
Refactored error handling and added authentication middleware
The error handling logic has been refactored into a new \errorz\ package, introducing a structured \APIError\ type with standard HTTP status codes and a \JoinError\ helper for wrapping errors. This new error system is integrated into the \responses\ package, which now correctly maps \APIError\ instances to appropriate HTTP status codes in JSON responses. Additionally, a new Cognito-based authentication middleware has been added to validate JWT tokens and inject user claims into the request context, while the router now includes CORS, Sentry error tracking, and a health check endpoint.
pkg · high confidence
Removal of Post entity
The Post entity, which previously defined the structure for posts with ID, Title, and Text fields, has been removed from the codebase.
entity · high confidence
Removal of legacy route handlers
The file containing route definitions and HTTP handlers for posts has been deleted. This removes the GetPosts and AddPost endpoints from the application, meaning users can no longer retrieve or create posts through these specific route handlers.
routes · high confidence
Removed Firestore-based PostRepository implementation
The file post\_repository.go, which contained the implementation for saving and retrieving posts using Google Cloud Firestore, has been deleted from the repository layer. This removes the previous data access logic for posts, likely as part of a broader refactoring or migration of the repository interface.
repository · high confidence
Dependencies
Updated Go module dependencies and runtime version
The Go module has been updated to use Go 1.22 (with toolchain 1.22.4) and includes a comprehensive set of dependency updates. New or upgraded packages include AWS SDK for Go v2 (S3, Cognito, SES), Sentry for error tracking, Gin web framework, GORM with MySQL driver, Viper configuration, Cobra CLI, and various utility libraries. This update modernizes the project's toolchain and third-party libraries.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 51 → 55 (+4.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 94 → 96 (+2.4)
- Architecture 100 → 95 (-5.0)
- Maturity 55 → 55 (+0.0)
- Readiness 50 → 48 (-1.7)
- Security 49 → 58 (+8.5)
- Domain Modelling 45 → 58 (+13.3)
Resolved (30)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (12 lines × 2) (pkg/services/cognito.go)
- Duplicated block (12 lines × 2) (pkg/services/s3.go)
- Duplicated block (17 lines × 2) (pkg/services/cognito.go)
- Duplicated block (20 lines × 2) (pkg/services/cognito.go)
- Duplicated block (8 lines × 2) (pkg/middlewares/upload_middleware.go)
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2024-2963 (go.mod)
- …and 10 more
New (66)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: github.com/nfnt/resize
- Deprecated module: github.com/aws/aws-sdk-go-v2/feature/s3/manager
- Deprecated module: github.com/lestrrat-go/jwx
- Duplicated block (13 lines × 2) (pkg/services/cognito.go)
- Duplicated block (13 lines × 2) (pkg/services/s3.go)
- Duplicated block (26 lines × 2) (pkg/services/cognito.go)
- Duplicated block (31 lines × 2) (pkg/services/cognito.go)
- Duplicated block (7–9 lines × 2) (pkg/middlewares/upload_middleware.go)
- Duplicated block (9 lines × 2) (pkg/framework/logger.go)
- High CVE: [GHSA redacted] (go.mod)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 46 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
wesionaryTEAM/go_clean_architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4e066f64367893350fa3448be861d975c12104ff — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.