Skip to content
CAI
Software that uses CAICheck a score

rails/webpacker

53.1

Adequate · 26 September 2026

982

lines of production code

Ruby

with JavaScript

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add Gemfiles for testing against multiple Rails versions

The project now includes dedicated Gemfiles to run the test suite against Rails 5.2, 6.0, 6.1, and the latest Rails edge/master branch. This enables developers to verify compatibility and run automated tests across these specific Rails versions.

gemfiles · high confidence

Introduce new Babel preset configuration for Webpacker

A new Babel preset is introduced at \package/babel/preset.js\, centralizing the Babel configuration for the project. This preset configures \@babel/preset-env\ with \modules: 'auto'\, \corejs: '3.8'\, and \bugfixes: true\ for development and production environments, while using \@babel/preset-typescript\ when TypeScript is present. It also includes \@babel/plugin-transform-runtime\ and validates the environment variable, providing a standardized way to handle transpilation and runtime support for the application.

package/babel · high confidence

Architecture

Refactored Webpacker architecture into modular classes

Webpacker's internal structure has been refactored from a monolithic, singleton-based approach into distinct, testable classes. The \Webpacker::Digests\ and \Webpacker::Source\ classes have been removed in favor of a new \Webpacker::Instance\ that manages separate components: \Webpacker::Configuration\ for settings, \Webpacker::Compiler\ for build logic, \Webpacker::Manifest\ for asset lookups, and \Webpacker::Commands\ for tasks like clean and compile. This change improves code organization and allows for multiple Webpacker configurations within the same application.

lib/webpacker · high confidence

Behavioural changes

Consolidate environment-specific JavaScript configs into a single YAML file

The separate JavaScript configuration files for development, production, and shared settings have been removed in favor of a unified \webpacker.yml\ configuration file. This change simplifies the default project structure by moving all Webpacker settings—including environment-specific options like \compile\, \dev\_server\, and \cache\_manifest\—into a single, easily editable YAML file, eliminating the need to maintain multiple JavaScript config files.

lib/install/config · high confidence

Extracted style rule generation into reusable utility functions

The \package/utils\ directory now includes \get\_style\_rule.js\ and \helpers.js\ to centralize logic for generating webpack style rules. This refactoring encapsulates the detection of \css-loader\ and \postcss-loader\ availability, as well as the construction of the loader chain (including \style-loader\ or \mini-css-extract-plugin\), making the build configuration more modular and consistent across development and production environments.

package/utils · high confidence

Refactored Webpacker into a modular, singleton-based architecture

The Webpacker library has been restructured from a single file into a modular architecture with separate classes for configuration, compilation, and commands, all accessed via a singleton instance. This change introduces a dedicated logger that routes output to stdout during specific operations and ensures NODE\_ENV is correctly scoped during compilation, which resolves issues with log output visibility and environment variable handling.

lib · high confidence

Refactored Webpacker rake tasks and added a dedicated Yarn task

The Webpacker rake tasks in lib/tasks have been restructured to use a centralized task description map, simplifying the :webpacker namespace and improving the output of the main task. A new lib/tasks/yarn.rake file was added to handle Yarn installation, providing a duplicate of the Yarn tasks from older Rails versions to ensure compatibility. The :compile task now outputs digests to a JSON file, and the overall task structure is cleaner and more maintainable.

lib/tasks · high confidence

Removed default application.js pack template

The default application.js pack template has been removed from the installation files. This means that new projects will no longer receive a pre-configured JavaScript entry point that automatically imports React, requiring users to manually set up their JavaScript bundling configuration if they wish to use it.

lib/install/javascript · high confidence

Reorganize Webpacker rake tasks into dedicated files

The Webpacker rake tasks have been reorganized into separate, dedicated files (e.g., \compile.rake\, \clean.rake\, \check\_node.rake\), each handling a specific responsibility such as verifying Node.js or Yarn versions, compiling assets, or cleaning build directories. This structural change improves maintainability and clarity of the build process without altering the external interface of the tasks.

lib/tasks/webpacker · high confidence

Replace shell-based binstubs with direct Ruby execution for improved performance and reliability

The binstubs in lib/install/bin have been rewritten to execute Ruby scripts directly rather than invoking them through the shell. This change removes the overhead associated with shell execution, resulting in faster startup times for the webpack, webpack-dev-server, and yarn binstubs. The new implementations also ensure that environment variables like RAILS\_ENV and NODE\_ENV are set correctly before running the respective runners, and the yarn binstub now explicitly searches for the yarn executable in the system PATH, providing a clearer error message if yarn is not installed.

lib/install/bin · high confidence

Restructured package configuration and environment handling

The package directory has been refactored to improve configuration management and environment handling. Configuration is now split into dedicated modules: \config.js\ handles loading and merging default and app-specific settings, \configPath.js\ resolves the config file location, and \env.js\ manages environment detection (NODE\_ENV, RAILS\_ENV). The \dev\_server.js\ module now allows dev server settings to be overridden by environment variables (e.g., \WEBPACKER\_DEV\SERVER\\*\). Additionally, \inliningCss.js\ provides logic to inline CSS during development, tied to the Webpacker instance. This restructuring clarifies how configuration is loaded and how environment variables influence the build and dev server behavior.

package · high confidence

Restructured webpack rule configuration into modular files

The webpack build rules for JavaScript, CSS, Sass, and other assets have been reorganized from a single configuration file into separate, modular files (e.g., \babel.js\, \css.js\, \sass.js\). This change improves maintainability and allows for easier configuration of individual asset types, such as enabling CSS modules or specifying custom paths for Sass and Less compilation.

package/rules · high confidence

Restructures webpack environment configuration into a modular base and environment-specific configs

The webpack configuration is refactored to use a shared base configuration (base.js) that is extended by environment-specific configs (development.js, production.js, test.js). This change introduces support for multiple files per entry point, enables Brotli compression in production, configures Terser for ES5 output, and sets up the dev server with configurable live reload and HMR options. The test environment is simplified to inherit from the base config.

package/environments · high confidence

Simplified Webpack configuration structure

The Webpack configuration files have been restructured to use a shared base configuration. Each environment-specific file (development, production, test) now sets the appropriate NODE\_ENV and requires the common base config, making the setup more modular and easier to maintain.

lib/install/config/webpack · high confidence

Updated Webpacker installer to support modern JavaScript tooling and Yarn 2

The installer script (lib/install/template.rb) was rewritten to handle the installation of Webpacker with a focus on Yarn 2 compatibility and modern Webpack configuration. It now copies the new \application.js\ entry point, generates a \webpacker.yml\ config, and sets up the \app/javascript\ directory structure. The script explicitly installs \webpack\, \webpack-cli\, and \webpack-dev-server\ as direct dependencies, and adds \node\_modules\ to the asset load path. It also updates the \bin/setup\ script to run \yarn\ and configures the Content Security Policy initializer to allow the webpack-dev-server host in development environments.

lib/install · medium confidence

Webpacker has been retired

The project has been officially retired. The README now directs users to alternative JavaScript solutions for Rails 7, such as jsbundling-rails or importmap-rails, and notes that security fixes will continue for the v5 gem but no new features will be added. Development of v6 is continuing under a new gem called Shakapacker.

(repo-wide) · high confidence

Test coverage

Add comprehensive test coverage for Webpacker core components; Add test application configuration files for Webpacker; Added a dummy Rails application for testing mountable engines; Added tests for Webpacker configuration and environment handling; Added unit tests for the base Webpack environment configuration.

Dependencies

Update Ruby and JavaScript dependencies

Updated the Ruby gemspec to require Ruby 2.7.0 or higher and Rails 5.2 or higher, while adding development dependencies for bundler, rubocop, and rubocop-performance. The package.json was updated to specify Node.js versions 12.13.0, 14, or 16+, and upgraded core dependencies including Webpack 5.53.0, Babel 7.15.5, and terser-webpack-plugin 5.2.4.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 44 → 53 (+9.2)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 54 → 50 (-4.9)
  • Architecture 69 → 69 (+0.0)
  • Maturity 57 → 48 (-9.8)
  • Readiness 30 → 64 (+34.1)
  • Security 55 → 70 (+14.9)

Resolved (72)

  • Change coupling: base.js ↔ base.js (package/environments/tests/base.js)
  • Change coupling: base.js ↔ helpers.js (package/environments/base.js)
  • Change coupling: config.js ↔ config.js (package/tests/config.js)
  • Change coupling: development.js ↔ index.js (package/environments/development.js)
  • Change coupling: development.js ↔ production.js (lib/install/config/webpack/development.js)
  • Change coupling: production.js ↔ helpers.js (package/environments/production.js)
  • Coverage not measured — test suite did not build
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • …and 52 more

New (66)

  • Ambiguous naming convention for bang methods. Similar to the non-bang variants, it is unclear if 'lookup!' is a distinct operation from 'lookup_pack_with_chunks!' or if it is a simplified version. The bang usually implies raising an error, but the difference in payload (chunks vs no chunks) is hidden in the name.
  • Ambiguous naming convention for lookup methods. The distinction between 'lookup' and 'lookup_pack_with_chunks' is not immediately clear from the signature alone, especially since 'lookup!' exists as a variant. It is unclear if 'lookup' returns a simplified object or if it is an alias for 'lookup_pack_with_chunks' with different error handling.
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical vulnerability: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • …and 46 more

Architecture

  • Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed

Added bounded contexts (1)

  • webpacker

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rails/webpacker was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a715e055d937748c7cfd34b0450295348ca13ee6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.