bibendi/modular-rails
48.5
Weak · 21 September 2026
4.5k
lines of production code
Ruby
primary language
4
measurements over time
What this system is
Features
Add authentication engine with user registration, login, and password management
Introduces the \auth\_by\ engine, providing a complete authentication solution. Users can now register new accounts, sign in with email and password, and manage their passwords (including reset via email). The engine exposes GraphQL mutations for sign-up, sign-in, sign-out, and token refresh, while also offering standard web controllers and views for password reset flows. It integrates with JWT sessions for stateless API authentication and includes database migrations for user security features like brute-force protection.
_engines/auth\by · high confidence
Database schema and seed data updates for Active Storage and user roles
The application now includes database migrations to support Active Storage features, specifically adding a 'service\_name' column to the 'active\_storage\_blobs' table and creating a new 'active\_storage\_variant\_records' table for image variants. Additionally, the system now provides seed data to automatically create default user accounts (admin, manager, and member) with associated avatars, facilitating initial setup and testing.
_engines/core\by/db · high confidence
Introduce user interests engine with GraphQL API
The \engines/interests\ module has been added, providing a new capability for users to manage their interests. Users can now add an interest via the \addUserInterest\ GraphQL mutation, which creates a new interest if it doesn't exist or links the user to an existing one. A corresponding \interests\ query allows fetching all known interests, and the \User\ type is extended to expose each user's list of interests. The engine also includes a subscriber that automatically assigns a default interest ('Sport') when a new user is created.
engines/interests · high confidence
Introduces GraphQL field extension for record transformation
A new \EntityFieldExt\ extension is added to the GraphQL layer to automatically transform object records before resolution. This change also updates the \CoreBy::GraphQL::Loaders::RecordLoader\ to use the fully qualified namespace, and the engine is configured to load the new \entity\_behaviour\ module and associated rake tasks.
_engines/core\by/lib · high confidence
New CI pipeline and dirty-check utility for modular monolith
The project now uses CircleCI for continuous integration, introducing a new .circleci/config.yml that defines workflows for checkout, bundle installation, security auditing, RuboCop, tests, and linters. A new .circleci/is-dirty Ruby script is added to detect changes in gems and engines, allowing the CI to skip unchanged components and run full test suites on the master branch.
.circleci · high confidence
Behavioural changes
Adopts Packwerk for dependency checking and updates Ruby version
The application now uses Packwerk to enforce package dependencies and privacy, with configuration files (packwerk.yml, package.yml) and load paths defining the structure for engines like CoreBy, AuthBy, and Interests. The Ruby version is upgraded from 2.7.2 to 2.7.4. Additionally, Yarn is removed from the build and development environment, and RuboCop is configured to exclude specific paths including a new SDK file.
(repo-wide) · high confidence
Database schema and seed configuration updates
The database schema was updated to include new tables for user interests and user-interest associations, alongside standard Active Storage and versioning tables. Additionally, the database seed file was modified to load seeds from the 'Core By' engine instead of the 'Tasks By' engine, reflecting a change in the application's modular structure.
db · medium confidence
Migrate GraphQL documentation and logging configuration
The application no longer generates or serves the Graphdoc static website, as the \graphdoc\_run\_time\ configuration and the \graphdoc.rb\ initializer have been removed. Instead, GraphQL documentation is now managed via a new \config/inflections.yml\ file that defines standard English inflections for terms like GraphQL, JWT, and SDK. Additionally, the Lograge logging context has been updated to apply to the new \core\_by/sdk\ controllers (\application\_controller\ and \api\_controller\) instead of the previous \core\_by/base\_controller\ and \core\_by/api/base\_controller\. Finally, the \/docs/graphql\ route for Graphdoc has been removed from the application routes.
config · medium confidence
Migrate controllers to use the new SDK base class
The application's controllers have been updated to inherit from the new SDK-provided base classes. Specifically, ApplicationController now extends CoreBy::SDK::ApplicationController, and HealthController now extends ApplicationController. This change aligns the controller hierarchy with the new public SDK structure, replacing the previous CoreBy::BaseController inheritance.
app/controllers · high confidence
Migrate core\_by engine classes to the shared SDK base classes
The \core\_by\ engine has been refactored to inherit from the shared \SDK\ namespace, replacing the previous \CoreBy\-specific base classes. Controllers, jobs, models, forms, and GraphQL types now extend from \SDK::ApplicationController\, \SDK::ApplicationJob\, \SDK::ApplicationRecord\, \SDK::ApplicationForm\, \SDK::ApplicationService\, and \SDK::Schema\ variants. This change standardizes the inheritance hierarchy, meaning these components now share common behavior and configuration provided by the SDK, rather than relying on local base classes like \BaseController\ or \BaseJob\. Additionally, the GraphQL schema's maximum complexity limit has been increased from 100 to 200, and the \ActiveSupport\ load hooks have been updated to reflect the new class structure.
_engines/core\by/app · high confidence
Refactor role constraint to use SDK user lookup
The role constraint logic in lib/routes\_utils/role\_constraint.rb was updated to replace the previous direct database query with a call to CoreBy::SDK::Users.find\_by\_id, checking the user's role against the allowed roles. This change shifts how user roles are retrieved and validated during request matching.
_lib/routes\utils · medium confidence
Refactored CoreBy SDK namespace and file structure
The CoreBy SDK components have been reorganized under a new \CoreBy::SDK\ namespace. This includes moving and renaming base classes and types (such as controllers, models, GraphQL types, and events) to their new locations within the \engines/core\_by/public\ directory. For example, \CoreBy::BaseController\ is now \CoreBy::SDK::ApplicationController\, and GraphQL types have been relocated from \CoreBy::Types\ to \CoreBy::SDK::Types\. This change updates the internal structure of the SDK, ensuring all related components are grouped under the \SDK\ module for better organization and clarity.
_engines/core\by/public · high confidence
Removal of Rake task for asset precompilation
The Rake task that previously handled asset precompilation, which also triggered database validation checks and graph documentation generation, has been removed from the application.
lib/tasks · high confidence
Removal of Yarn integration and build commands
The project has removed support for Yarn as a JavaScript dependency manager. The \bin/yarn\ executable has been deleted, and the \bin/setup\ script no longer installs JavaScript dependencies via Yarn. Additionally, the \bin/engem\ CLI tool has been updated to remove the \yarn\ command and the \build\ command, which previously installed dependencies and ran linters and tests. Users will no longer be able to use the \engem yarn\ or \engem build\ commands, and the initial setup process will not automatically install JavaScript dependencies.
bin · high confidence
Update generated gem metadata and test configuration
Templates for generated gems and engines now set the default version to 1.0.0 and update the author to "Evil Martians". The engine generator includes a new package.yml template that enforces dependencies and privacy, and explicitly depends on engines/core\_by. Test helpers are updated to enable Active Job and Active Storage test adapters, and PaperTrail's RSpec framework is required to speed up tests. Database URLs in the test configuration now use the engine name directly instead of the "vicinity" prefix.
lib/generators · high confidence
Test coverage
Added comprehensive test suite for the CoreBy engine; Added test suite for application configuration and logging; Updated test helpers and configuration in common-testing.
Dependencies
Add auth\_by and interests engines with new dependencies
Introduced two new Rails engines, auth\_by and interests, each with their own gemspec and development dependencies. The auth\_by engine adds dependencies on jwt\_sessions, pg, rails, slim-rails, and sorcery, while the interests engine depends on pg, rails, and core\_by. The core\_by engine was updated to include new GraphQL-related dependencies (action\_policy-graphql, graphql, graphql-connections, graphql-fragment\_cache, graphql-persisted\_queries) and resonad. Additionally, packwerk was added as a linter dependency, graphdoc-ruby and sentry-raven were removed, and the project's package.json (and thus Yarn) was removed.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 53 → 49 (-4.2)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 99 (-1.2)
- Architecture 100 → 85 (-15.4)
- Maturity 47 → 47 (+0.0)
- Readiness 49 → 47 (-1.4)
- Security 71 → 69 (-1.9)
- Domain Modelling 48 → 48 (+0.0)
- Accessibility 45 (new)
Resolved (36)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical vulnerability: [GHSA redacted] (Gemfile.lock)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- …and 16 more
New (112)
- Banned license: sidekiq
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical vulnerability: [GHSA redacted] (Gemfile.lock)
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- Documentation: no usage examples (docs/development/docker.md)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- …and 92 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
bibendi/modular-rails was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 46f7abe9701000f6c0abf6adcbf822045831a054 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.