prisma/prisma
53.1
Adequate · 29 July 2026
192k
lines of production code
TypeScript
with JavaScript
2
measurements over time
How this codebase got here
Score
- CAI 37 → 53 (+16.3)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.
Lenses
- Code Health 80 → 84 (+3.9)
- Architecture 24 → 42 (+18.5)
- Maturity 61 → 93 (+32.0)
- Readiness 37 → 51 (+13.9)
- Security 41 → 62 (+20.7)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 70 (new)
Resolved (141)
- Boundary-crossing change coupling: jest.config.js ↔ jest.config.js (packages/cli/jest.config.js)
- Boundary-crossing change coupling: jest.config.js ↔ jest.config.js (packages/cli/jest.config.js)
- Boundary-crossing change coupling: jest.config.js ↔ jest.config.js (packages/integration-tests/jest.config.js)
- Boundary-crossing change coupling: libsql.ts ↔ neon.ts (packages/adapter-libsql/src/libsql.ts)
- Boundary-crossing change coupling: libsql.ts ↔ pg.ts (packages/adapter-libsql/src/libsql.ts)
- Boundary-crossing change coupling: libsql.ts ↔ planetscale.ts (packages/adapter-libsql/src/libsql.ts)
- Boundary-crossing change coupling: neon.ts ↔ pg.ts (packages/adapter-neon/src/neon.ts)
- Boundary-crossing change coupling: neon.ts ↔ planetscale.ts (packages/adapter-neon/src/neon.ts)
- Boundary-crossing change coupling: pg.ts ↔ planetscale.ts (packages/adapter-pg/src/pg.ts)
- Boundary-crossing change coupling: wasm.ts ↔ build.ts (packages/client-generator-ts/src/utils/wasm.ts)
- Critical CVE: [GHSA redacted] (packages/client/tests/e2e/prisma-client-generator/enums-tsoa/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (packages/client/tests/e2e/browser-bundle/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (packages/client/tests/e2e/unsupported-browser-error/tests/pnpm-lock.yaml)
- Dependency hygiene not measured — no supported dependency manifest was read
- Further orphaned files (smaller)
- High CVE: [GHSA redacted] (packages/client/tests/e2e/unsupported-browser-error/tests/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (packages/client/tests/e2e/nextjs-schema-not-found/5_simplerepo-noServerComponents-customOutput-noReExport/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (packages/client/tests/e2e/nextjs-schema-not-found/5_simplerepo-noServerComponents-customOutput-noReExport/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (packages/client/tests/e2e/prisma-client-generator/enums-tsoa/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (packages/client/tests/e2e/enum-import-in-edge/pnpm-lock.yaml)
- …and 121 more
New (263)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 001 - Migrations as Edges.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 002 - Plans are Immutable.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 003 - One Query One Statement.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 004 - Storage Hash vs Profile Hash.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 005 - Thin Core Fat Targets.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 006 - Dual Authoring Modes.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 007 - Types Only Emission.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 008 - Dev Auto Emit CI Explicit Emit.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 009 - Deterministic Naming Scheme.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 010 - Canonicalization Rules.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 011 - Unified Plan Model.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 012 - Raw SQL Escape Hatch.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 013 - Lane Agnostic Plan Identity.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 014 - Runtime Hook API.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 015 - ORM as Optional Extension.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 016 - Adapter SPI for Lowering.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 017 - Extension Compatibility Policy.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 018 - Plan Annotations Schema.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 019 - TypedSQL as Separate CLI.md)
- ADR lacks an enforcement field (docs/architecture docs/adrs/ADR 020 - Result Typing Rules.md)
- …and 243 more
Changes since last survey
- 52 commits — 50 feature/other, 2 fixes
By area
- (root) — 9 commits
- packages/1-framework — 7 commits
- packages/3-targets — 7 commits
- packages/2-sql — 6 commits
- packages/3-extensions — 5 commits
- test/integration — 4 commits
- .github/workflows — 3 commits
- examples/prisma-next-demo — 2 commits
- projects/lsp-interpreter-diagnostics — 2 commits
- projects/remove-db-attributes — 2 commits
- docs/planning — 1 commit
- projects/codec-json-projections — 1 commit
- projects/functional-indexes — 1 commit
- projects/prisma-8-rc1 — 1 commit
- skills-contrib/review-fetch-phase — 1 commit
Notable commits
- fix: TML-3069: wrap driver cursor streaming in an explicit transaction to fix the portal C_N flake (#1017)
- fix: fix: resolve open CodeQL alerts (shell command construction, table-cell escaping, workflow permissions) (#1026)
- change: Add per-codec temporal presets with execution-default arguments (TML-3036) (#1003)
- change: Bump to version 0.16.0 (#1019)
- change: Drop the sha256: prefix from all content hashes (TML-2756) (#1033)
- change: Every SQL index is name-identified — wire names, expression/partial capture, rename convergence (#1047)
- change: Expression, partial, and unique indexes are authorable in PSL and TypeScript (#1048)
- change: Port prisma & prisma-engines test corpus into prisma-next (488 accounted) (#1035)
- change: Port prisma functional wave 2: mongo composites, relationMode matrices, issue regressions (229 accounted) (#1042)
- change: TML-2462: rename extensionPacks → extensions; freeze-window config-key sweep (#1032)
- change: TML-2979: Scope MTI variant predicates in count writes (#940)
- change: TML-2984: close out lsp-interpreter-diagnostics — pattern doc, QA proof, retro landings, project deletion (#1012)
- change: TML-2984: surface config-load failures on the config URI; retain the last-good project on reload failure (#974)
- change: TML-2986: unify PSL scalar types and add native scalar constructors (#1022)
- change: TML-2987: migrate the repository to bare PSL native types (#1036)
- change: TML-2988: Hard-cut @db.* lowering; add actionable diagnostics (#1054)
- change: TML-3037: contract infer output round-trips through contract emit (#1011)
- change: TML-3060: plan 4-stage lossless codec JSON migration (#1013)
- change: TML-3061: PostgreSQL and SQLite codec descriptor protocols (#1051)
- change: TML-3067: all error codes become dotted NAMESPACE.SUBCODE (ADR 239) (#1016)
- …and 32 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
prisma/prisma was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d5192b16980275c75ca57b3b83e45b6311273e9b — the exact code this score is about.
- Scored under rubric-2026.08.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.