Skip to content
CAI
Software that uses CAICheck a score

bibendi/modular-rails

48.5

Weak · 21 September 2026

4.5k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add authentication engine with user registration, login, and password management

Introduces the \auth\_by\ engine, providing a complete authentication solution. Users can now register new accounts, sign in with email and password, and manage their passwords (including reset via email). The engine exposes GraphQL mutations for sign-up, sign-in, sign-out, and token refresh, while also offering standard web controllers and views for password reset flows. It integrates with JWT sessions for stateless API authentication and includes database migrations for user security features like brute-force protection.

_engines/auth\by · high confidence

Database schema and seed data updates for Active Storage and user roles

The application now includes database migrations to support Active Storage features, specifically adding a 'service\_name' column to the 'active\_storage\_blobs' table and creating a new 'active\_storage\_variant\_records' table for image variants. Additionally, the system now provides seed data to automatically create default user accounts (admin, manager, and member) with associated avatars, facilitating initial setup and testing.

_engines/core\by/db · high confidence

Introduce user interests engine with GraphQL API

The \engines/interests\ module has been added, providing a new capability for users to manage their interests. Users can now add an interest via the \addUserInterest\ GraphQL mutation, which creates a new interest if it doesn't exist or links the user to an existing one. A corresponding \interests\ query allows fetching all known interests, and the \User\ type is extended to expose each user's list of interests. The engine also includes a subscriber that automatically assigns a default interest ('Sport') when a new user is created.

engines/interests · high confidence

Introduces GraphQL field extension for record transformation

A new \EntityFieldExt\ extension is added to the GraphQL layer to automatically transform object records before resolution. This change also updates the \CoreBy::GraphQL::Loaders::RecordLoader\ to use the fully qualified namespace, and the engine is configured to load the new \entity\_behaviour\ module and associated rake tasks.

_engines/core\by/lib · high confidence

New CI pipeline and dirty-check utility for modular monolith

The project now uses CircleCI for continuous integration, introducing a new .circleci/config.yml that defines workflows for checkout, bundle installation, security auditing, RuboCop, tests, and linters. A new .circleci/is-dirty Ruby script is added to detect changes in gems and engines, allowing the CI to skip unchanged components and run full test suites on the master branch.

.circleci · high confidence

Behavioural changes

Adopts Packwerk for dependency checking and updates Ruby version

The application now uses Packwerk to enforce package dependencies and privacy, with configuration files (packwerk.yml, package.yml) and load paths defining the structure for engines like CoreBy, AuthBy, and Interests. The Ruby version is upgraded from 2.7.2 to 2.7.4. Additionally, Yarn is removed from the build and development environment, and RuboCop is configured to exclude specific paths including a new SDK file.

(repo-wide) · high confidence

Database schema and seed configuration updates

The database schema was updated to include new tables for user interests and user-interest associations, alongside standard Active Storage and versioning tables. Additionally, the database seed file was modified to load seeds from the 'Core By' engine instead of the 'Tasks By' engine, reflecting a change in the application's modular structure.

db · medium confidence

Migrate GraphQL documentation and logging configuration

The application no longer generates or serves the Graphdoc static website, as the \graphdoc\_run\_time\ configuration and the \graphdoc.rb\ initializer have been removed. Instead, GraphQL documentation is now managed via a new \config/inflections.yml\ file that defines standard English inflections for terms like GraphQL, JWT, and SDK. Additionally, the Lograge logging context has been updated to apply to the new \core\_by/sdk\ controllers (\application\_controller\ and \api\_controller\) instead of the previous \core\_by/base\_controller\ and \core\_by/api/base\_controller\. Finally, the \/docs/graphql\ route for Graphdoc has been removed from the application routes.

config · medium confidence

Migrate controllers to use the new SDK base class

The application's controllers have been updated to inherit from the new SDK-provided base classes. Specifically, ApplicationController now extends CoreBy::SDK::ApplicationController, and HealthController now extends ApplicationController. This change aligns the controller hierarchy with the new public SDK structure, replacing the previous CoreBy::BaseController inheritance.

app/controllers · high confidence

Migrate core\_by engine classes to the shared SDK base classes

The \core\_by\ engine has been refactored to inherit from the shared \SDK\ namespace, replacing the previous \CoreBy\-specific base classes. Controllers, jobs, models, forms, and GraphQL types now extend from \SDK::ApplicationController\, \SDK::ApplicationJob\, \SDK::ApplicationRecord\, \SDK::ApplicationForm\, \SDK::ApplicationService\, and \SDK::Schema\ variants. This change standardizes the inheritance hierarchy, meaning these components now share common behavior and configuration provided by the SDK, rather than relying on local base classes like \BaseController\ or \BaseJob\. Additionally, the GraphQL schema's maximum complexity limit has been increased from 100 to 200, and the \ActiveSupport\ load hooks have been updated to reflect the new class structure.

_engines/core\by/app · high confidence

Refactor role constraint to use SDK user lookup

The role constraint logic in lib/routes\_utils/role\_constraint.rb was updated to replace the previous direct database query with a call to CoreBy::SDK::Users.find\_by\_id, checking the user's role against the allowed roles. This change shifts how user roles are retrieved and validated during request matching.

_lib/routes\utils · medium confidence

Refactored CoreBy SDK namespace and file structure

The CoreBy SDK components have been reorganized under a new \CoreBy::SDK\ namespace. This includes moving and renaming base classes and types (such as controllers, models, GraphQL types, and events) to their new locations within the \engines/core\_by/public\ directory. For example, \CoreBy::BaseController\ is now \CoreBy::SDK::ApplicationController\, and GraphQL types have been relocated from \CoreBy::Types\ to \CoreBy::SDK::Types\. This change updates the internal structure of the SDK, ensuring all related components are grouped under the \SDK\ module for better organization and clarity.

_engines/core\by/public · high confidence

Removal of Rake task for asset precompilation

The Rake task that previously handled asset precompilation, which also triggered database validation checks and graph documentation generation, has been removed from the application.

lib/tasks · high confidence

Removal of Yarn integration and build commands

The project has removed support for Yarn as a JavaScript dependency manager. The \bin/yarn\ executable has been deleted, and the \bin/setup\ script no longer installs JavaScript dependencies via Yarn. Additionally, the \bin/engem\ CLI tool has been updated to remove the \yarn\ command and the \build\ command, which previously installed dependencies and ran linters and tests. Users will no longer be able to use the \engem yarn\ or \engem build\ commands, and the initial setup process will not automatically install JavaScript dependencies.

bin · high confidence

Update generated gem metadata and test configuration

Templates for generated gems and engines now set the default version to 1.0.0 and update the author to "Evil Martians". The engine generator includes a new package.yml template that enforces dependencies and privacy, and explicitly depends on engines/core\_by. Test helpers are updated to enable Active Job and Active Storage test adapters, and PaperTrail's RSpec framework is required to speed up tests. Database URLs in the test configuration now use the engine name directly instead of the "vicinity" prefix.

lib/generators · high confidence

Test coverage

Added comprehensive test suite for the CoreBy engine; Added test suite for application configuration and logging; Updated test helpers and configuration in common-testing.

Dependencies

Add auth\_by and interests engines with new dependencies

Introduced two new Rails engines, auth\_by and interests, each with their own gemspec and development dependencies. The auth\_by engine adds dependencies on jwt\_sessions, pg, rails, slim-rails, and sorcery, while the interests engine depends on pg, rails, and core\_by. The core\_by engine was updated to include new GraphQL-related dependencies (action\_policy-graphql, graphql, graphql-connections, graphql-fragment\_cache, graphql-persisted\_queries) and resonad. Additionally, packwerk was added as a linter dependency, graphdoc-ruby and sentry-raven were removed, and the project's package.json (and thus Yarn) was removed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 53 → 49 (-4.2)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-1.2)
  • Architecture 100 → 85 (-15.4)
  • Maturity 47 → 47 (+0.0)
  • Readiness 49 → 47 (-1.4)
  • Security 71 → 69 (-1.9)
  • Domain Modelling 48 → 48 (+0.0)
  • Accessibility 45 (new)

Resolved (36)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical vulnerability: [GHSA redacted] (Gemfile.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • …and 16 more

New (112)

  • Banned license: sidekiq
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical vulnerability: [GHSA redacted] (Gemfile.lock)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no project overview (README.md)
  • Documentation: no usage examples (docs/development/docker.md)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • …and 92 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bibendi/modular-rails was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 46f7abe9701000f6c0abf6adcbf822045831a054 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.