heartcombo/simple_form
73.8
Strong · 26 September 2026
3.3k
lines of production code
Ruby
primary language
4
measurements over time
What this system is
Features
Add default form templates for ERB, Haml, and Slim
The Simple Form generator now includes default form templates for ERB, Haml, and Slim. These templates display validation errors using the new \f.error\_notification\ helper and organize inputs and actions within \.form-inputs\ and \.form-actions\ divs, providing a consistent starting point for form generation across different template engines.
_lib/generators/simple\form/templates · high confidence
Enable SimpleForm helpers on default Rails form builders
The SimpleForm library now includes \simple\_form\_for\ and \simple\_fields\_for\ methods that can be used within standard Rails \form\_for\ and \fields\_for\ blocks. This allows developers to use SimpleForm's input helpers and wrappers on top of the default Rails form builder, providing a way to gradually adopt SimpleForm features without rewriting all existing form code.
_lib/simple\_form/action\_view\extensions · high confidence
Migrate documentation and project files to Markdown and modernize build tasks
The project's documentation and metadata have been modernized: the RDoc-based README and CHANGELOG have been replaced with Markdown versions (README.md, CHANGELOG.md), while the old .rdoc and .mdoc files have been removed. Additionally, the Rakefile has been updated to use Bundler's gem tasks and conditional RDoc loading, and the .gitignore file has been added to exclude build artifacts and IDE files.
(repo-wide) · high confidence
Architecture
Refactor SimpleForm into a modular component-based architecture
SimpleForm has been refactored into a modular structure where form elements like labels, errors, and hints are now distinct components. The library now uses a \MapType\ module to handle input type mappings and provides a \FormBuilder\ that composes these components. This change introduces new files such as \components.rb\, \helpers.rb\, and \wrappers.rb\ to support this new architecture, allowing for more flexible form generation and easier customization of individual form parts.
_lib/simple\form · high confidence
Behavioural changes
Add Rails 7.0, 7.1, 7.2, 8.0, and main branch test configurations
The project now includes dedicated Gemfile configurations for testing against specific Rails versions (7.0, 7.1, 7.2, and 8.0) as well as the Rails main branch. Each configuration pins the corresponding versions of activemodel, actionpack, and railties to match the target Rails release, ensuring compatibility across these versions.
gemfiles · high confidence
Extracted form rendering logic into dedicated components
The rendering logic for form elements has been extracted into dedicated components (such as Errors, Hints, Labels, Maxlength, Minlength, Pattern, Placeholders, Readonly, and HTML5). This refactoring separates concerns within the SimpleForm library, making the codebase more modular and easier to maintain. For users, this change is primarily internal, but it enables more granular control over form rendering and sets the stage for future enhancements to individual form parts.
_lib/simple\form/components · high confidence
Major configuration and architecture overhaul for Simple Form
The library's configuration API has been significantly expanded and restructured. The main entry point now explicitly requires ActionView and ActionPack, and utilizes ActiveSupport::Autoload for lazy loading components, helpers, and inputs. A large number of new configuration options have been added, including error\_method, error\_notification\_tag/class, collection\_wrapper\_tag/class, item\_wrapper\_tag/class, label\_class, boolean\_style, default\_form\_class, generate\_additional\_classes\_for, required\_by\_default, browser\_validations, input\_mappings, wrapper\_mappings, custom\_inputs\_namespaces, time\_zone/country priorities, translate\_labels, inputs\_discovery, cache\_discovery, button\_class, and input\_class. Additionally, deprecation warnings were added for the file\_methods and the old method signature for input methods.
lib · high confidence
New wrappers API for form components
The library introduces a new wrappers API that allows users to define form layouts using a block-based builder syntax. This new system replaces the previous configuration method, enabling more flexible and explicit control over how components like labels, inputs, and hints are rendered and wrapped in HTML. Users can now use \b.use\, \b.optional\, and \b.wrapper\ within \config.wrappers\ blocks to define the structure of their forms.
_lib/simple\form/wrappers · high confidence
Refactor form helper logic into dedicated modules
The logic for handling form field states has been extracted from the main helpers into separate, dedicated modules: Autofocus, Disabled, Readonly, Required, and Validators. This refactoring isolates the detection of these states (e.g., \has\_disabled?\, \required\_by\_validators?\) into their own files, improving code organization and maintainability without changing the user-facing behavior of the form builder.
_lib/simple\form/helpers · medium confidence
Refactored input classes into a modular component-based architecture
The input classes have been restructured to use a component-based architecture, where features like HTML5 attributes, placeholders, and validation states are handled by separate modules (e.g., \SimpleForm::Components::HTML5\, \SimpleForm::Components::Placeholders\). This change introduces a new \Base\ class that composes these components, allowing for more granular control over input behavior. Users can now enable or disable specific input features (like \placeholder\ or \required\) via class-level \enable\ and \disable\ methods, and the framework automatically applies appropriate HTML5 attributes and CSS classes based on the active components.
_lib/simple\form/inputs · high confidence
Simplified SimpleForm installation with framework-specific options
The SimpleForm installation generator has been refactored to support optional configuration for Bootstrap 5 and Zurb Foundation 5. When running the generator, users can now pass the \--bootstrap\ or \--foundation\ flags to automatically include the respective wrapper configurations. If neither option is selected, the generator prints a message informing the user about these framework-specific configurations. The generator also supports specifying a template engine (erb, haml, or slim) to copy the appropriate form template.
_lib/generators/simple\form · medium confidence
Updated SimpleForm initializer templates for Bootstrap 5 and Foundation 3
The default SimpleForm initializer template has been updated to include configuration for validation classes on input fields, specifically setting \input\_field\_error\_class\ to 'is-invalid' and \input\_field\_valid\_class\ to 'is-valid'. Additionally, the Bootstrap 5 initializer template has been updated to support Bootstrap 5 styling, including updated CSS classes for form controls, error notifications, and boolean inputs. The Foundation 3 initializer template has also been updated to reflect the correct CSS classes for that framework.
_lib/generators/simple\form/templates/config/initializers · high confidence
Test coverage
Add generator tests for SimpleForm; Added bin/test script for improved test runner features; Added comprehensive test coverage for form builder and form helper behaviors; Added test support files for form components and models; Added tests for custom components and label generation; Comprehensive test coverage for the form builder components; Expanded test coverage for form input components; Modernized test environment and added SimpleForm setup tests.
Dependencies
Update Rails dependencies to 8.1.0
The Gemfile now specifies Rails 8.1.0 for actionpack, activemodel, and railties, and the gemspec declares dependencies on Rails 7.0 or higher. This update aligns the project with the latest Rails releases, ensuring compatibility with modern Rails applications while maintaining support for older versions.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 51 → 74 (+22.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 98 (-1.6)
- Architecture 94 → 90 (-4.0)
- Maturity 59 → 63 (+3.6)
- Readiness 25 → 77 (+51.4)
- Security 85 → 88 (+2.9)
Resolved (7)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- No tests found
- Test reliability not included
New (23)
- Ambiguous naming convention for boolean checks. 'has_errors?' clearly refers to the presence of validation errors on the object. 'has_value?' is ambiguous: it could mean 'does the attribute have a value?', 'is the field required?', or 'are there errors associated with this specific value?'. Given the context of other methods like 'valid?' and 'has_hint?', 'has_value?' is likely intended to mean 'is the input populated?', but the name conflicts with standard Ruby conventions where 'has_value?' often implies existence of a key in a hash or presence of data.
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Duplicated block (7 lines × 2) (lib/simple_form/components/maxlength.rb)
- FormBuilder.build_association_attribute (cognitive 16) (lib/simple_form/form_builder.rb)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent naming for text extraction methods. 'label_text' and 'placeholder_text' both extract the text content for their respective components. However, 'SimpleForm.Components.Labels.label(wrapper_options)' renders the label, while 'SimpleForm.Components.Placeholders.placeholder(wrapper_options)' renders the placeholder. The '_text' suffix is used for both, which is consistent, but the base methods ('label' vs 'placeholder') are not parallel in their component hierarchy (Labels is a component, Placeholders is a component). This is minor, but 'label_text' might be confused with 'label' if one assumes 'label' returns the text object. A more consistent pattern would be 'label_content' and 'placeholder_content' or ensuring the base method name clearly indicates rendering vs text extraction.
- Low CVE: [GHSA redacted] (Gemfile.lock)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- Medium: security finding (details withheld)
- No dependency advisory monitoring
- Orphaned files with no living knowledge
- Outdated: actionpack
- Outdated: activemodel
- Outdated: railties
- …and 3 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
heartcombo/simple_form was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 18f38aad0bdeca2ba1815043b94d96fdbbe6a325 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.