Skip to content
CAI
Software that uses CAICheck a score

prisma/prisma

53.1

Adequate · 29 July 2026

192k

lines of production code

TypeScript

with JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

How this codebase got here

Score

  • CAI 37 → 53 (+16.3)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

Lenses

  • Code Health 80 → 84 (+3.9)
  • Architecture 24 → 42 (+18.5)
  • Maturity 61 → 93 (+32.0)
  • Readiness 37 → 51 (+13.9)
  • Security 41 → 62 (+20.7)
  • Domain Modelling 100 → 100 (+0.0)
  • Accessibility 70 (new)

Resolved (141)

  • Boundary-crossing change coupling: jest.config.js ↔ jest.config.js (packages/cli/jest.config.js)
  • Boundary-crossing change coupling: jest.config.js ↔ jest.config.js (packages/cli/jest.config.js)
  • Boundary-crossing change coupling: jest.config.js ↔ jest.config.js (packages/integration-tests/jest.config.js)
  • Boundary-crossing change coupling: libsql.ts ↔ neon.ts (packages/adapter-libsql/src/libsql.ts)
  • Boundary-crossing change coupling: libsql.ts ↔ pg.ts (packages/adapter-libsql/src/libsql.ts)
  • Boundary-crossing change coupling: libsql.ts ↔ planetscale.ts (packages/adapter-libsql/src/libsql.ts)
  • Boundary-crossing change coupling: neon.ts ↔ pg.ts (packages/adapter-neon/src/neon.ts)
  • Boundary-crossing change coupling: neon.ts ↔ planetscale.ts (packages/adapter-neon/src/neon.ts)
  • Boundary-crossing change coupling: pg.ts ↔ planetscale.ts (packages/adapter-pg/src/pg.ts)
  • Boundary-crossing change coupling: wasm.ts ↔ build.ts (packages/client-generator-ts/src/utils/wasm.ts)
  • Critical CVE: [GHSA redacted] (packages/client/tests/e2e/prisma-client-generator/enums-tsoa/pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (packages/client/tests/e2e/browser-bundle/pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (packages/client/tests/e2e/unsupported-browser-error/tests/pnpm-lock.yaml)
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Further orphaned files (smaller)
  • High CVE: [GHSA redacted] (packages/client/tests/e2e/unsupported-browser-error/tests/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (packages/client/tests/e2e/nextjs-schema-not-found/5_simplerepo-noServerComponents-customOutput-noReExport/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (packages/client/tests/e2e/nextjs-schema-not-found/5_simplerepo-noServerComponents-customOutput-noReExport/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (packages/client/tests/e2e/prisma-client-generator/enums-tsoa/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (packages/client/tests/e2e/enum-import-in-edge/pnpm-lock.yaml)
  • …and 121 more

New (263)

  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 001 - Migrations as Edges.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 002 - Plans are Immutable.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 003 - One Query One Statement.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 004 - Storage Hash vs Profile Hash.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 005 - Thin Core Fat Targets.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 006 - Dual Authoring Modes.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 007 - Types Only Emission.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 008 - Dev Auto Emit CI Explicit Emit.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 009 - Deterministic Naming Scheme.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 010 - Canonicalization Rules.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 011 - Unified Plan Model.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 012 - Raw SQL Escape Hatch.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 013 - Lane Agnostic Plan Identity.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 014 - Runtime Hook API.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 015 - ORM as Optional Extension.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 016 - Adapter SPI for Lowering.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 017 - Extension Compatibility Policy.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 018 - Plan Annotations Schema.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 019 - TypedSQL as Separate CLI.md)
  • ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 020 - Result Typing Rules.md)
  • …and 243 more

Changes since last survey

  • 52 commits — 50 feature/other, 2 fixes

By area

  • (root) — 9 commits
  • packages/1-framework — 7 commits
  • packages/3-targets — 7 commits
  • packages/2-sql — 6 commits
  • packages/3-extensions — 5 commits
  • test/integration — 4 commits
  • .github/workflows — 3 commits
  • examples/prisma-next-demo — 2 commits
  • projects/lsp-interpreter-diagnostics — 2 commits
  • projects/remove-db-attributes — 2 commits
  • docs/planning — 1 commit
  • projects/codec-json-projections — 1 commit
  • projects/functional-indexes — 1 commit
  • projects/prisma-8-rc1 — 1 commit
  • skills-contrib/review-fetch-phase — 1 commit

Notable commits

  • fix: TML-3069: wrap driver cursor streaming in an explicit transaction to fix the portal C_N flake (#1017)
  • fix: fix: resolve open CodeQL alerts (shell command construction, table-cell escaping, workflow permissions) (#1026)
  • change: Add per-codec temporal presets with execution-default arguments (TML-3036) (#1003)
  • change: Bump to version 0.16.0 (#1019)
  • change: Drop the sha256: prefix from all content hashes (TML-2756) (#1033)
  • change: Every SQL index is name-identified — wire names, expression/partial capture, rename convergence (#1047)
  • change: Expression, partial, and unique indexes are authorable in PSL and TypeScript (#1048)
  • change: Port prisma & prisma-engines test corpus into prisma-next (488 accounted) (#1035)
  • change: Port prisma functional wave 2: mongo composites, relationMode matrices, issue regressions (229 accounted) (#1042)
  • change: TML-2462: rename extensionPacks → extensions; freeze-window config-key sweep (#1032)
  • change: TML-2979: Scope MTI variant predicates in count writes (#940)
  • change: TML-2984: close out lsp-interpreter-diagnostics — pattern doc, QA proof, retro landings, project deletion (#1012)
  • change: TML-2984: surface config-load failures on the config URI; retain the last-good project on reload failure (#974)
  • change: TML-2986: unify PSL scalar types and add native scalar constructors (#1022)
  • change: TML-2987: migrate the repository to bare PSL native types (#1036)
  • change: TML-2988: Hard-cut @db.* lowering; add actionable diagnostics (#1054)
  • change: TML-3037: contract infer output round-trips through contract emit (#1011)
  • change: TML-3060: plan 4-stage lossless codec JSON migration (#1013)
  • change: TML-3061: PostgreSQL and SQLite codec descriptor protocols (#1051)
  • change: TML-3067: all error codes become dotted NAMESPACE.SUBCODE (ADR 239) (#1016)
  • …and 32 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

prisma/prisma was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d5192b16980275c75ca57b3b83e45b6311273e9b — the exact code this score is about.
  • Scored under rubric-2026.08.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.