Skip to content
CAI
Software that uses CAICheck a score

rails/importmap-rails

61.9

Adequate · 20 September 2026

905

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Ruby gem that integrates JavaScript import maps into Rails applications, managing package pinning, vendoring, and asset pipeline integration. It provides CLI tools for package management and helpers for generating secure, cached script tags with CSP nonce support. The library ensures compatibility across multiple Rails versions and asset pipelines while handling automatic reloading in development environments.

Features

Add default importmap configuration template

A new default configuration file for importmap is installed, which pins the 'application' module by default. This establishes the baseline setup for module mapping in the application.

lib/install/config · high confidence

Removals

Drop bundled ES Module Shims library

The application no longer ships with the bundled ES Module Shims JavaScript library (specifically version 0.12.2). This removes the local implementation of import maps and dynamic import polyfills, meaning the application now relies on external sources or native browser support for these features rather than the previously included shim code.

app/assets · high confidence

Behavioural changes

Add Importmap::Freshness controller concern

A new controller concern, Importmap::Freshness, has been added to the application. It provides a stale\_when\_importmap\_changes method that sets an ETag based on the digest of the import map, enabling HTTP caching invalidation when the import map changes for HTML requests.

app/controllers · high confidence

Conditional engine loading and new reloader requirement

The library now explicitly requires the \importmap/reloader\ module and conditionally loads the \importmap/engine\ only when the \Rails::Railtie\ constant is defined. This ensures the engine is not loaded in non-Rails contexts and introduces the reloader component, which supports the auto-reload functionality for importmaps and JavaScript files.

lib · high confidence

Enforced version argument and explicit RubyGems publishing host

The release script now requires a version number to be passed as an argument, exiting with a usage message if omitted. Additionally, the script explicitly pushes the built gem to rubygems.org using the --host flag and removes the local gem file after pushing, ensuring consistent publishing behavior.

bin · high confidence

Enhanced importmap security, caching, and CLI capabilities

The importmap-rails library now supports automatic Subresource Integrity (SRI) hash calculation for local assets when enabled, improving security against tampering. It introduces a more robust caching mechanism with configurable keys and a file watcher sweeper for development environments to ensure maps update correctly. Additionally, new CLI commands allow users to audit packages for vulnerabilities and check for outdated versions directly from the command line.

importmap-rails · high confidence

Installer now uses importmap-rails helpers and modern JavaScript paths

The installation process has been updated to integrate with the importmap-rails gem. Instead of manually managing an importmap JSON file, the installer now inserts the \javascript\_importmap\_tags\ helper into the application layout and creates an \app/javascript/application.js\ entry point. It also ensures the \vendor/javascript\ directory exists for pinned modules and updates the Sprockets manifest to include JavaScript files from both the new \app/javascript\ and \vendor/javascript\ directories. The legacy \importmap\_include\_tags\ helper and the old installer logic have been removed.

lib/install · high confidence

Major version 2.2.3 release with CLI overhaul and new management commands

The library has been updated to version 2.2.3, introducing a significant behavioral change through a new command-line interface built on Thor. Users can now manage their import maps directly via the \bin/importmap\ executable, which supports new commands to \pin\ and \unpin\ packages, \pristine\ (redownload all pinned packages), \audit\ (check for security vulnerabilities), \outdated\ (list outdated packages), \update\ (upgrade outdated pins), and \packages\ (list package versions). The internal architecture has shifted to use a dedicated \Packager\ class for handling package downloads and vendor file management, and the previous \ImportmapHelper\ has been removed in favor of a new \Reloader\ that watches for changes in development and test environments. The engine now configures asset paths for \app/javascript\ and \vendor/javascript\ and integrates with Propshaft and Sprockets for rescuable asset errors.

lib/importmap · high confidence

Refactor importmap tag helpers to support inline maps, preloading, and CSP nonces

The \javascript\_importmap\_tags\ helper has been updated to generate an inline importmap script tag instead of linking to an external JSON file, which improves performance and compatibility. The helper now automatically includes Content Security Policy (CSP) nonces on all generated script and link tags to support stricter security policies. Additionally, it generates module preload tags for dependencies marked for preloading, enhancing load times for modern browsers, and allows specifying a custom importmap object or entry point.

app/helpers · high confidence

Updated importmap:install task to use Rake::Task invocation

The \importmap:install\ rake task now invokes the \app:template\ task via \Rake::Task\[\].invoke\ instead of executing a subshell command. This change avoids reloading the rakefile during execution and updates the installer script path from \installer.rb\ to \install.rb\.

lib/tasks · high confidence

Test coverage

Added test dummy application for integration testing; Added test suite for importmap-rails commands and helpers; Expanded test matrix and configuration for Rails 6.1 through 8.1.

Dependencies

Expanded Rails version and asset pipeline test matrix

The gemfile test matrix has been expanded to include support for Rails 8.0 and 8.1, alongside existing versions 6.1, 7.0, 7.1, and 7.2. Each version is tested with both the Propshaft and Sprockets asset pipelines to ensure compatibility across different asset management strategies. Additionally, a new gemfile targets the Rails main branch to validate against upcoming development versions.

gemfiles · high confidence

Update dependencies and drop Rails monolith requirement

The gem now requires Ruby 3.1 or higher and has shifted its runtime dependencies from the full 'rails' gem to specific components (railties, activesupport, actionpack). This change, combined with the addition of 'propshaft' as a dependency, aligns the gem with modern Rails asset handling. The test suite has also been expanded to include 'turbo-rails', 'stimulus-rails', and 'minitest-mock', and the gem's source code URI has been updated to the new 'rails/importmap-rails' repository.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 62.

Lenses

  • Code Health 100
  • Architecture 69
  • Maturity 61
  • Readiness 54
  • Security 77

Changes since last survey

  • 300 commits — 265 feature/other, 35 fixes

By area

  • (root) — 117 commits
  • lib/importmap — 68 commits
  • (repo) — 36 commits
  • app/assets — 27 commits
  • app/helpers — 9 commits
  • .github/workflows — 8 commits
  • lib/install — 5 commits
  • test/dummy — 5 commits
  • test/npm_test.rb — 4 commits
  • gemfiles/rails_7_propshaft.gemfile.lock — 3 commits
  • lib/tasks — 3 commits
  • bin/refresh — 2 commits
  • bin/release — 2 commits
  • test/fixtures — 2 commits
  • test/importmap_tags_helper_test.rb — 2 commits
  • .github/prompts — 1 commit
  • bin/update-shim — 1 commit
  • gemfiles/rails_7_0_propshaft.gemfile.lock — 1 commit
  • lib/importmap-rails.rb — 1 commit
  • test/installer_test.rb — 1 commit

Notable commits

  • fix: Add an additional test, improve the error check to fix the tests
  • fix: Fix ./bin/importmap update (#262)
  • fix: Fix 302/304 mixup (#260)
  • fix: Fix README ruby syntax error (#70)
  • fix: Fix broken bin/importmap json command (#39)
  • fix: Fix character group for package target
  • fix: Fix extra lockfiles again & update release script to handle that automatically (#77)
  • fix: Fix minified 1.3.2
  • fix: Fix missing space in README (#90)
  • fix: Fix missing version bump for propshaft lockfile
  • fix: Fix net http request on ruby 2.7 (#130)
  • fix: Fix nonce attributes that were accidentally broken in 243fbfb (#143)
  • fix: Fix pin_all_from incorrectly removing "js" substring from filenames
  • fix: Fix reference to renamed pin/unpin option (#64)
  • fix: Fix regex
  • fix: Fix reloader test flakiness (#141)
  • fix: Fix some paths
  • fix: Fix test with Rails main
  • fix: Fix the assets.paths for the tests
  • fix: Fix the scan when the pinned package has a version and has options after it
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rails/importmap-rails was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6fb2bd58e3709d4996179de06aa687d6abae8a0e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.