Skip to content
CAI
Software that uses CAICheck a score

aasm/aasm

58.3

Adequate · 26 September 2026

2.9k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release delivers AASM 6.0, a major version upgrade featuring a completely new DSL, global callbacks, and thread-safe state machine storage. The internal architecture has been significantly refactored into modular classes, and the persistence layer now supports transactional operations across multiple ORMs. Additionally, the release introduces new Rails generators for ActiveRecord, Mongoid, and NoBrainer, alongside comprehensive test coverage for all supported databases and callback behaviors.

Features

AASM 6.0.0: New DSL, global callbacks, and thread-safe state machine storage

The AASM library has been upgraded to version 6.0.0, introducing a completely new Domain Specific Language (DSL) for defining state machines. This update adds global event and transaction callbacks (e.g., \before\_all\_events\, \after\_all\_transitions\) that apply across all events. The internal state machine storage is now thread-safe, utilizing \Concurrent::Map\ to prevent race conditions in multi-threaded environments. Additionally, the library now supports namespacing for reader methods and constants, and provides a \permitted\_transitions\ method to inspect allowed transitions for the current state.

lib/aasm · high confidence

Add AASM Rails generators for ActiveRecord and Mongoid

New Rails generators have been introduced for both ActiveRecord and Mongoid, allowing users to quickly scaffold models with AASM state machine support. The generators automatically include the AASM module, define the necessary state column (defaulting to 'aasm\_state'), and handle model creation only if it does not already exist. This simplifies the initial setup of state machines in new or existing models.

lib/generators/aasm · high confidence

Add Minitest assertions for AASM state machine testing

The AASM library now provides a set of Minitest assertions to simplify testing state machines. New helper methods are available for verifying allowed events (assert\_event\_allowed/refute\_event\_allowed), checking if transitions to specific states are permitted (assert\_transition\_to\_allowed/refute\_transition\_to\_allowed), confirming the current state (assert\_have\_state/refute\_have\_state), and validating state transitions from a given state (assert\_transitions\_from/refute\_transitions\_from).

lib/aasm/minitest · high confidence

Add RSpec matchers for AASM state machine assertions

Adds four new RSpec custom matchers to the \lib/aasm/rspec\ directory to improve testing of state machine behavior. The \allow\_event\ matcher verifies that a specific event can be fired, supporting custom parameters via a \with\ chain. The \allow\_transition\_to\ matcher checks if a state is reachable. The \have\_state\ matcher asserts the current state of the object. The \transition\_from\ matcher verifies that a specific event causes a transition from a given state to an expected destination state, also supporting event arguments. These additions allow users to write more expressive and readable tests for their AASM state machines.

lib/aasm/rspec · high confidence

New AASM generator for ActiveRecord models

A new generator has been added to create AASM state machines for ActiveRecord models. Running the generator will automatically create the necessary migration (either adding a state column to an existing table or creating a new one) and inject the AASM configuration into the model class, streamlining the setup of state management in Rails applications.

_lib/generators/active\record · high confidence

Architecture

Refactored AASM core architecture and added NoBrainer generator

The library's internal structure has been significantly reorganized: the previous flat file layout (e.g., lib/event.rb, lib/state.rb) has been replaced with a modular 'aasm/' directory structure (e.g., aasm/core/transition, aasm/core/event) and a new configuration class. This refactoring introduces a more robust state machine implementation with improved inheritance support and callback invokers. Additionally, a new Rails generator for NoBrainer (RethinkDB) has been added to help users scaffold models with AASM support.

lib · high confidence

Behavioural changes

AASM 6.0: Breaking changes for namespaced events and persistence warnings

AASM 6.0 introduces several breaking changes. First, namespaced event methods no longer define plain-named methods (e.g., \sell\ is replaced by \sell\_car\), requiring users to update their code to use the full namespaced method names. Second, \whiny\_persistence\ now defaults to \true\, meaning bang events (\run!\) will raise an exception if the object fails persistence (e.g., validation errors), whereas before it would silently return \false\. Third, support for Ruby 2 and Rails 6 has been dropped. Additionally, the repository structure has been updated with new documentation files (README\_FROM\_VERSION\_3\_TO\_4.md, README\_FROM\_VERSION\_5\_TO\_6.md) and a Dockerfile for testing.

(repo-wide) · high confidence

Add Rails 8.0 and update test suite dependencies

The gemfiles directory now includes a new configuration for Rails 8.0, enabling the library to be tested against this latest version. Additionally, the test suite dependencies have been updated: Minitest is locked to version 5.x, and the 'after\_commit\_everywhere' gem is used in place of the removed 'after\_commit\_action' gem. The 'redis-objects' dependency is also explicitly pinned to version 1.6.0.

gemfiles · medium confidence

Refactor AASM core into new classes

The AASM core logic has been refactored into new classes: Event, Invoker, State, and Transition. This change restructures how callbacks are invoked and managed internally, providing a more modular and testable foundation for state machine operations. The Invoker class now handles the dispatching of literal, proc, class, and array-based callbacks, while the Event and Transition classes manage their respective callback lifecycles more explicitly.

lib/aasm/core · high confidence

Refactored callback invokers to support keyword arguments

The callback invoker classes (BaseInvoker, ClassInvoker, LiteralInvoker, and ProcInvoker) have been refactored to properly detect and pass keyword arguments to callbacks. This change ensures that callbacks expecting keyword arguments will receive them correctly, fixing issues where keyword arguments were previously ignored or passed incorrectly, particularly in Ruby 3.2+ environments.

lib/aasm/core/invokers · high confidence

Refactored persistence layer with transactional support and ORM-specific implementations

The persistence logic has been restructured into a modular architecture, introducing a shared \AASM::Persistence::ORM\ module that provides transactional support (including nested transaction handling and pessimistic locking) for ActiveRecord and Sequel. Each ORM (ActiveRecord, Mongoid, Redis, etc.) now has its own dedicated persistence file implementing the new interface, ensuring consistent state initialization and validation behavior across all supported databases.

lib/aasm/persistence · high confidence

Updated Active Record migration templates to use versioned inheritance

The Active Record migration templates (migration.rb and migration\_existing.rb) have been updated to use versioned inheritance (e.g., \ActiveRecord::Migration\[6.0\]\) instead of the default. This ensures that the generated migrations are compatible with modern Rails versions that require explicit version specification for migration classes.

_lib/generators/active\record/templates · high confidence

Test coverage

Add comprehensive test models for ActiveRecord integration; Added Minitest support for state machine assertions; Added NoBrainer (RethinkDB) model specs; Added Sequel model specs for transactions, locking, and validation; Added comprehensive test fixtures for Mongoid state machine models; Added generator tests for ActiveRecord, Mongoid, and NoBrainer; Added test coverage for the Process model's state machine; Added test fixtures for AASM state machines; Added test fixtures for Redis model examples; Added test infrastructure for ActiveRecord and Dynamoid models; Added unit tests for AASM persistence backends; Added unit tests for invoker classes; Added unit tests for state machine behavior; Expanded test coverage for AASM callback mechanisms; Refactor test helpers for ORMs and caches.

Dependencies

Updated gemspec to require Ruby 3 and Rails 7.1

The aasm gemspec now requires Ruby version 3 or higher, reflecting the project's shift away from older Ruby versions. Additionally, the Gemfile has been updated to include Rails 7.1.5 as a development dependency, aligning the project's testing and development environment with the latest Rails release.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 47 → 58 (+11.0)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-1.1)
  • Architecture 94 → 80 (-14.2)
  • Maturity 61 → 56 (-4.1)
  • Readiness 19 → 44 (+25.0)
  • Security 76 → 91 (+15.2)

Resolved (14)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High IaC: DS-0029 (Dockerfile)
  • High IaC: DS-0029 (Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0026 (Dockerfile)
  • No exposed public API
  • No tests found
  • Test reliability not included
  • The Usage section's optional args parameter can be omitted, but if you define initialize; you must accept the model instance as the first parameter to it. This detail is buried in a nested subsection under 'Callbacks' and not immediately visible from the top-level index. (README.md)

New (32)

  • AASM.aasm_fired (cognitive 18) (lib/aasm/aasm.rb)
  • Duplicate functionality for humanizing event names. Base.human_event_name(event) and Localizer.human_event_name(klass, event) appear to do the same thing. The Base method likely delegates to Localizer, but exposing both creates a confusing API surface where users don't know which to use.
  • Duplicated block (6 lines × 2) (lib/aasm/persistence/mongoid_persistence.rb)
  • Event._fire (cognitive 16) (lib/aasm/core/event.rb)
  • High IaC: DS-0029 (Dockerfile)
  • High IaC: DS-0029 (Dockerfile)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent exception handling pattern: fire vs fire!. While fire! likely raises on failure and fire returns false/nil, this is a common Ruby pattern, but the documentation/signature doesn't explicitly clarify the return value difference in the signature itself. However, a more significant inconsistency is the lack of a unified trigger or execute method. fire is specific to 'events', but InstanceBase also has set_current_state_with_persistence. The naming fire is consistent with the Event type, but the existence of fire! suggests a need for a consistent *! convention across other mutating operations if they exist (none do here, so this is minor). The real issue is the duplication of intent between may_fire_event? and the internal logic of fire.
  • Low CVE: [GHSA redacted] (Gemfile)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • …and 12 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

aasm/aasm was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 88061ec5104adf50a9b4c590ca58999df23cdb76 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.