rails/importmap-rails
61.9
Adequate · 20 September 2026
905
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is a Ruby gem that integrates JavaScript import maps into Rails applications, managing package pinning, vendoring, and asset pipeline integration. It provides CLI tools for package management and helpers for generating secure, cached script tags with CSP nonce support. The library ensures compatibility across multiple Rails versions and asset pipelines while handling automatic reloading in development environments.
Features
Add default importmap configuration template
A new default configuration file for importmap is installed, which pins the 'application' module by default. This establishes the baseline setup for module mapping in the application.
lib/install/config · high confidence
Removals
Drop bundled ES Module Shims library
The application no longer ships with the bundled ES Module Shims JavaScript library (specifically version 0.12.2). This removes the local implementation of import maps and dynamic import polyfills, meaning the application now relies on external sources or native browser support for these features rather than the previously included shim code.
app/assets · high confidence
Behavioural changes
Add Importmap::Freshness controller concern
A new controller concern, Importmap::Freshness, has been added to the application. It provides a stale\_when\_importmap\_changes method that sets an ETag based on the digest of the import map, enabling HTTP caching invalidation when the import map changes for HTML requests.
app/controllers · high confidence
Conditional engine loading and new reloader requirement
The library now explicitly requires the \importmap/reloader\ module and conditionally loads the \importmap/engine\ only when the \Rails::Railtie\ constant is defined. This ensures the engine is not loaded in non-Rails contexts and introduces the reloader component, which supports the auto-reload functionality for importmaps and JavaScript files.
lib · high confidence
Enforced version argument and explicit RubyGems publishing host
The release script now requires a version number to be passed as an argument, exiting with a usage message if omitted. Additionally, the script explicitly pushes the built gem to rubygems.org using the --host flag and removes the local gem file after pushing, ensuring consistent publishing behavior.
bin · high confidence
Enhanced importmap security, caching, and CLI capabilities
The importmap-rails library now supports automatic Subresource Integrity (SRI) hash calculation for local assets when enabled, improving security against tampering. It introduces a more robust caching mechanism with configurable keys and a file watcher sweeper for development environments to ensure maps update correctly. Additionally, new CLI commands allow users to audit packages for vulnerabilities and check for outdated versions directly from the command line.
importmap-rails · high confidence
Installer now uses importmap-rails helpers and modern JavaScript paths
The installation process has been updated to integrate with the importmap-rails gem. Instead of manually managing an importmap JSON file, the installer now inserts the \javascript\_importmap\_tags\ helper into the application layout and creates an \app/javascript/application.js\ entry point. It also ensures the \vendor/javascript\ directory exists for pinned modules and updates the Sprockets manifest to include JavaScript files from both the new \app/javascript\ and \vendor/javascript\ directories. The legacy \importmap\_include\_tags\ helper and the old installer logic have been removed.
lib/install · high confidence
Major version 2.2.3 release with CLI overhaul and new management commands
The library has been updated to version 2.2.3, introducing a significant behavioral change through a new command-line interface built on Thor. Users can now manage their import maps directly via the \bin/importmap\ executable, which supports new commands to \pin\ and \unpin\ packages, \pristine\ (redownload all pinned packages), \audit\ (check for security vulnerabilities), \outdated\ (list outdated packages), \update\ (upgrade outdated pins), and \packages\ (list package versions). The internal architecture has shifted to use a dedicated \Packager\ class for handling package downloads and vendor file management, and the previous \ImportmapHelper\ has been removed in favor of a new \Reloader\ that watches for changes in development and test environments. The engine now configures asset paths for \app/javascript\ and \vendor/javascript\ and integrates with Propshaft and Sprockets for rescuable asset errors.
lib/importmap · high confidence
Refactor importmap tag helpers to support inline maps, preloading, and CSP nonces
The \javascript\_importmap\_tags\ helper has been updated to generate an inline importmap script tag instead of linking to an external JSON file, which improves performance and compatibility. The helper now automatically includes Content Security Policy (CSP) nonces on all generated script and link tags to support stricter security policies. Additionally, it generates module preload tags for dependencies marked for preloading, enhancing load times for modern browsers, and allows specifying a custom importmap object or entry point.
app/helpers · high confidence
Updated importmap:install task to use Rake::Task invocation
The \importmap:install\ rake task now invokes the \app:template\ task via \Rake::Task\[\].invoke\ instead of executing a subshell command. This change avoids reloading the rakefile during execution and updates the installer script path from \installer.rb\ to \install.rb\.
lib/tasks · high confidence
Test coverage
Added test dummy application for integration testing; Added test suite for importmap-rails commands and helpers; Expanded test matrix and configuration for Rails 6.1 through 8.1.
Dependencies
Expanded Rails version and asset pipeline test matrix
The gemfile test matrix has been expanded to include support for Rails 8.0 and 8.1, alongside existing versions 6.1, 7.0, 7.1, and 7.2. Each version is tested with both the Propshaft and Sprockets asset pipelines to ensure compatibility across different asset management strategies. Additionally, a new gemfile targets the Rails main branch to validate against upcoming development versions.
gemfiles · high confidence
Update dependencies and drop Rails monolith requirement
The gem now requires Ruby 3.1 or higher and has shifted its runtime dependencies from the full 'rails' gem to specific components (railties, activesupport, actionpack). This change, combined with the addition of 'propshaft' as a dependency, aligns the gem with modern Rails asset handling. The test suite has also been expanded to include 'turbo-rails', 'stimulus-rails', and 'minitest-mock', and the gem's source code URI has been updated to the new 'rails/importmap-rails' repository.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 62.
Lenses
- Code Health 100
- Architecture 69
- Maturity 61
- Readiness 54
- Security 77
Changes since last survey
- 300 commits — 265 feature/other, 35 fixes
By area
- (root) — 117 commits
- lib/importmap — 68 commits
- (repo) — 36 commits
- app/assets — 27 commits
- app/helpers — 9 commits
- .github/workflows — 8 commits
- lib/install — 5 commits
- test/dummy — 5 commits
- test/npm_test.rb — 4 commits
- gemfiles/rails_7_propshaft.gemfile.lock — 3 commits
- lib/tasks — 3 commits
- bin/refresh — 2 commits
- bin/release — 2 commits
- test/fixtures — 2 commits
- test/importmap_tags_helper_test.rb — 2 commits
- .github/prompts — 1 commit
- bin/update-shim — 1 commit
- gemfiles/rails_7_0_propshaft.gemfile.lock — 1 commit
- lib/importmap-rails.rb — 1 commit
- test/installer_test.rb — 1 commit
Notable commits
- fix: Add an additional test, improve the error check to fix the tests
- fix: Fix ./bin/importmap update (#262)
- fix: Fix 302/304 mixup (#260)
- fix: Fix README ruby syntax error (#70)
- fix: Fix broken bin/importmap json command (#39)
- fix: Fix character group for package target
- fix: Fix extra lockfiles again & update release script to handle that automatically (#77)
- fix: Fix minified 1.3.2
- fix: Fix missing space in README (#90)
- fix: Fix missing version bump for propshaft lockfile
- fix: Fix net http request on ruby 2.7 (#130)
- fix: Fix nonce attributes that were accidentally broken in 243fbfb (#143)
- fix: Fix pin_all_from incorrectly removing "js" substring from filenames
- fix: Fix reference to renamed pin/unpin option (#64)
- fix: Fix regex
- fix: Fix reloader test flakiness (#141)
- fix: Fix some paths
- fix: Fix test with Rails main
- fix: Fix the assets.paths for the tests
- fix: Fix the scan when the pinned package has a version and has options after it
- …and 280 more
Architecture
- 0 containers · 1 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
rails/importmap-rails was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6fb2bd58e3709d4996179de06aa687d6abae8a0e — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.