railsadminteam/rails_admin
47.2
Weak · 26 September 2026
8.1k
lines of production code
Ruby
with JavaScript
5
measurements over time
What this system is
This system is RailsAdmin, a Ruby gem that provides a configurable admin interface for managing data in Rails applications. It supports both ActiveRecord and Mongoid backends, offering comprehensive CRUD operations, bulk actions, and export capabilities. The system integrates with popular authorization and auditing libraries like CanCanCan, Pundit, and PaperTrail, while providing a modern, responsive UI built on Bootstrap 5 and Hotwired Turbo.
How it got here
2010 — Rails 3 Engine migration and modernization
33 changes.
The project migrated from a standard Rails application structure into a Rails 3 Engine, removing legacy configuration files, scripts, and dependencies like Prototype. This period established coding standards, refactored the adapter layer to separate model introspection from data access, and modernized the UI by switching to Bootstrap 5 and ERB templates.
2011–2012 — Modern asset pipeline and ORM expansion
27 changes.
This period focused on modernizing RailsAdmin's asset handling by decoupling it from legacy bundlers and introducing explicit support for modern pipelines like Propshaft and Webpacker. Significant architectural work included adding a dedicated Mongoid adapter and built-in extensions for CanCanCan, Pundit, and PaperTrail. The effort was heavily supported by a comprehensive expansion of the test suite, covering new adapters, configuration modules, and integration scenarios.
2013–2021 — Modernization and test expansion
22 changes.
This period focused on modernizing the Rails Admin codebase by migrating JavaScript to ES Modules with Turbo and Bootstrap 5, and introducing a flexible CSS theming system. Significant effort was also dedicated to expanding test coverage across adapters, authorization integrations, and UI widgets, while refactoring the ActiveRecord adapter for better modularity and compatibility.
2026 — Asset prebuilding and code quality enforcement
5 changes.
This period focused on eliminating client-side build requirements by shipping precompiled JavaScript and CSS assets, thereby simplifying integration for applications. Concurrently, stricter RuboCop cops were introduced to enforce better separation of concerns in the RailsAdmin adapter and model access layers. The work was supported by expanded test coverage for period criteria handling and head customization hooks.
Features
Add CanCanCan authorization adapter for Rails Admin
Users can now authorize Rails Admin access and actions using the CanCanCan gem. A new \AuthorizationAdapter\ in the \lib/rails\_admin/extensions/cancancan\ directory integrates with CanCanCan's ability system, allowing administrators to define permissions via standard CanCanCan rules. The adapter handles controller-level access checks, per-action authorization (such as create, edit, or delete), query scoping based on user permissions, and attribute initialization for new records, ensuring that the admin interface respects the defined CanCanCan abilities.
_lib/rails\admin/extensions/cancancan · high confidence
Add field factories for ActionText, ActiveStorage, Shrine, and other attachment libraries
Rails Admin now automatically detects and renders fields for ActionText rich text areas, ActiveStorage attachments, and file uploads managed by Shrine, CarrierWave, Dragonfly, and Paperclip. It also adds support for Devise encrypted passwords and ActiveRecord enums. This allows users to edit these specific attribute types directly in the admin interface without manual configuration.
_lib/rails\admin/config/fields/factories · high confidence
Added Docker and deployment configuration for the dummy app
The dummy application now includes a Dockerfile, fly.toml, and associated configuration files (.dockerignore, .gitignore, Procfile.dev) to support containerized builds and deployment on Fly.io. This setup enables the dummy app to be built as a production-ready image, precompiling assets and configuring the environment for deployment, while also providing a development Procfile for local server execution.
_spec/dummy\app · high confidence
Introduce PaperTrail auditing adapter with configurable version classes
Adds a new \AuditingAdapter\ for the PaperTrail extension that enables history tracking with support for custom version classes and explicit user class configuration. The adapter maps PaperTrail fields to RailsAdmin columns, handles pagination via Kaminari with fallbacks, and eager-loads associations to prevent N+1 queries, allowing users to view and sort audit logs for models using PaperTrail's custom version class feature.
_lib/rails\_admin/extensions/paper\trail · high confidence
Introduce RailsAdmin controller hierarchy with configurable parent and authorization hooks
The RailsAdmin admin interface now uses a dedicated \ApplicationController\ that inherits from a configurable parent controller (defaulting to \ApplicationController\), allowing seamless integration with existing authentication and authorization systems. This base controller enforces authentication, authorization, and auditing via configurable hooks (\authenticate\_with\, \authorize\_with\, \audit\_with\) and provides a customizable \current\_user\ method. The \MainController\ handles all CRUD and bulk actions, delegating to specific action definitions and enforcing visibility and authorization checks per action. This structure centralizes security logic and makes the admin interface extensible for custom auth requirements.
app/controllers · high confidence
Introduce dedicated Mongoid adapter layer
RailsAdmin now includes a complete, dedicated adapter for Mongoid, splitting the previous logic into specific components: Association, Property, Reflection, Repository, Bson parsing, and StatementBuilder. This enables proper support for Mongoid-specific features such as embedded relations (embeds\_one/embeds\_many), polymorphic associations, custom primary keys, and BSON ObjectId handling, while ensuring compatibility with modern Mongoid versions (including 7.0+) and the BSON gem 5.0.0.
_lib/rails\admin/adapters/mongoid · high confidence
New Rake tasks for asset building and CI environment preparation
Added two new Rake tasks under the \rails\_admin\ namespace to improve development and CI workflows. The \rails\_admin:build\_assets\ task compiles precompiled assets shipped with the gem using npm, while \rails\_admin:verify\_assets\ ensures these assets are up to date by checking for uncommitted changes in \app/assets/builds\. Additionally, the \rails\_admin:prepare\_ci\_env\ task configures the database environment for GitHub Actions CI runs by generating a \database.yml\ file with settings for SQLite, PostgreSQL, or MySQL adapters based on the \CI\_DB\_ADAPTER\ environment variable.
lib/tasks · high confidence
New authorization and auditing extensions with composite key URL support
Rails Admin now includes built-in extensions for CanCanCan and Pundit authorization, as well as PaperTrail auditing, allowing users to integrate these popular gems directly. Additionally, the UrlForExtension ensures that composite primary keys are correctly serialized into URLs, resolving issues where composite IDs were not handled properly by the URL generation logic.
_lib/rails\admin/extensions · high confidence
New field types for ActionText, Active Storage, and ActiveRecord Enum
The RailsAdmin admin interface now includes dedicated field types for ActionText (using the Trix editor), Active Storage (supporting single and multiple file uploads with thumbnails and direct upload support), and ActiveRecord Enum (providing proper parsing and display of enum attributes). These additions allow administrators to edit rich text content, manage cloud-stored attachments, and interact with model enums directly within the form views.
_lib/rails\admin/config/fields/types · high confidence
New theming system with CSS custom properties
RailsAdmin now exposes a set of CSS custom properties (e.g., --ra-avatar-size, --ra-nav-link-active-bg) in the base styles, allowing users to retheme the interface by overriding these variables in their own stylesheets without needing to rebuild the asset bundle. This change introduces a new theming architecture via new files like theming.scss and variables.scss, replacing the previous hardcoded style approach with a more flexible, variable-driven system.
_src/rails\admin/styles/base · high confidence
Removals
Removed empty ApplicationHelper module
The empty ApplicationHelper module has been removed from the application. This cleanup eliminates an unused helper file that contained no methods or logic.
app/helpers · high confidence
Architecture
RailsAdmin adapters refactored into modular Reflection and Repository components
The adapter layer has been restructured to separate model introspection (Reflection) from data access (Repository), with shared query logic moved into StatementBuilder and WhereBuilder. This change improves maintainability and consistency across ActiveRecord and Mongoid adapters, ensuring that both ORM backends use a unified approach for building queries, handling associations, and managing column types.
_lib/rails\admin/adapters · high confidence
Behavioural changes
Migrate RailsAdmin UI to Bootstrap 5 and ERB templates
The RailsAdmin interface has been updated to use Bootstrap 5 classes, replacing the previous Twitter Bootstrap styling. This change includes converting all layout and view templates from HAML to ERB, introducing a new responsive navigation bar with collapsible sidebar support, and adding accessibility improvements such as ARIA labels for pagination. Users will see a modernized UI with better mobile responsiveness and consistent styling across the admin panel.
app/views/layouts · high confidence
Migration to Rails 3 Engine architecture
The application has been refactored from a standard Rails application structure into a Rails 3 Engine. This involves removing the legacy \config/application.rb\, \config/boot.rb\, and \config/environment.rb\ files, and updating \config/routes.rb\ to draw routes within the \RailsAdmin::Engine\ namespace. The routing logic has also been modernized to use Rails 3 route helpers and dynamic action mapping based on configuration, replacing the previous static route definitions.
config · high confidence
Modernize Rails configuration and add Mongoid support
The application's configuration has been updated to support Mongoid embedded relations by introducing new initializers for ActiveRecord and Mongoid extensions, while removing the legacy \secret\_token\ and \session\_store\ initializers in favor of standard Rails configuration methods. Users can now configure RailsAdmin directly within model classes via the new \rails\_admin\ method on ActiveRecord::Base, and the system automatically includes Mongoid extensions when the Mongoid gem is present.
config/initializers · high confidence
New Pundit authorization adapter with question-suffixed policy checks
The Pundit integration now uses a dedicated \AuthorizationAdapter\ that ensures policy checks are performed using question-suffixed methods (e.g., \create?\ instead of \create\), aligning with Pundit 2.x conventions. This change improves compatibility with modern Pundit versions and ensures that authorization decisions in list, create, and bulk actions correctly reflect the user's permissions as defined in their policies.
_lib/rails\admin/extensions/pundit · high confidence
New RuboCop cops for RailsAdmin adapter and model access
Added three new RuboCop cops (\AdapterReference\, \RawModelAccess\, \RecordDecoration\) to enforce stricter separation of concerns in RailsAdmin. \AdapterReference\ flags direct references to adapter classes (e.g., \RailsAdmin::Adapters::...\), \RawModelAccess\ prevents bypassing the abstract model facade by calling methods directly on the underlying model class (suggesting replacements like \dummy\_record\ instead of \new\), and \RecordDecoration\ prohibits modifying record instances via \extend\ or singleton methods to ensure they remain standard model instances.
rubocop · high confidence
New development and CI configuration files
The repository now includes configuration files for Prettier, RSpec, RuboCop, YARD, and the Appraisals tool, alongside a new CONTRIBUTING guide and a .teatro.yml for live demo staging. These files establish the project's coding standards, test execution parameters (including random order to catch order-dependency bugs), and multi-version Rails testing matrix, while the Rakefile has been refactored to use Bundler and RSpec directly instead of loading the Rails application environment.
(repo-wide) · high confidence
Proxy class now inherits from BasicObject to preserve bindings
The configuration proxy class has been refactored to inherit from BasicObject instead of Object. This change ensures that the bindings passed to the proxy are correctly preserved and applied when delegating method calls to the underlying object, fixing an issue where bindings were lost during proxying.
_lib/rails\admin/config/proxyable · high confidence
Rails Admin ActiveRecord adapter refactored into modular components
The ActiveRecord adapter has been split into distinct classes (Association, Property, Reflection, Repository, StatementBuilder, WhereBuilder) to improve code organization and maintainability. This refactoring introduces support for composite primary keys, fixes polymorphic association handling, and ensures correct nullability checks for foreign keys. Users benefit from more robust handling of complex associations and improved compatibility with newer Rails versions.
_lib/rails\_admin/adapters/active\record · high confidence
Rails Admin views migrated to ERB and updated for Bootstrap 5 and Turbo
The Rails Admin interface views have been converted from HAML to ERB and updated to support Bootstrap 5 and Turbo. This migration introduces a new dashboard with a model activity table and history section, adds a bulk delete feature, and implements inline add/edit capabilities for association fields. Form rendering now uses Bootstrap 5 components, including a new boolean toggle widget, and integrates with ActionText for rich text editing. The list view now supports horizontal scrolling for wide tables, and the export view allows users to select specific fields and configure CSV options.
_app/views/rails\admin · high confidence
RailsAdmin 4.0.0 beta: Adapter layer split and Turbo support
RailsAdmin has been upgraded to version 4.0.0 beta, introducing a major architectural change where the internal adapter layer is split into separate Reflection and Repository classes to better separate model introspection from data access. The engine now includes built-in support for Turbo Drive, and the configuration system has been updated to support lazy model loading and a new \included\_models\ allowlist. Additionally, the engine now enforces the presence of required middlewares (cookies, flash, method override, and session store) at initialization, raising an error if they are missing to prevent runtime failures in API mode.
_lib/rails\admin · high confidence
RailsAdmin 5.0 deprecation warnings and YAML loading fallbacks
RailsAdmin now emits deprecation warnings via ActiveSupport::Deprecation for version 5.0, allowing applications to configure or silence these messages independently. Additionally, the library implements a backwards-compatible YAML loading mechanism that attempts to use SafeYAML first, falls back to YAML.safe\_load if available, and raises a clear error if neither is present, ensuring robust configuration loading across different environments.
lib · high confidence
RailsAdmin JavaScript assets migrated to ESM with Turbo and Bootstrap 5 support
The RailsAdmin JavaScript bundle has been completely rewritten to use ES Modules, replacing the previous Sprockets-based asset pipeline. This migration introduces Hotwired Turbo for navigation, upgrades the UI framework from Bootstrap 3/4 to Bootstrap 5, and replaces jQuery UI's datetimepicker with Flatpickr. The new structure includes dedicated modules for filtering, nested forms, and remote modals, ensuring compatibility with modern JavaScript bundlers like esbuild and Importmaps while maintaining existing admin interface functionality.
_src/rails\admin · high confidence
RailsAdmin UI refreshed with Bootstrap 5 and Font Awesome 6
The RailsAdmin interface has been updated to use Bootstrap 5 and Font Awesome 6, replacing the previous icon set and styling framework. This change modernizes the visual appearance of components such as filtering selects, multiselects, and widgets, ensuring better compatibility with current web standards and improved consistency across the admin dashboard.
_src/rails\admin/styles · high confidence
RailsAdmin configuration DSL restructured into modular components
The configuration system in lib/rails\_admin/config has been refactored from a monolithic structure into distinct, modular components (actions, fields, sections, and mixins like Configurable and Hideable). This change introduces a factory-based field loading system that supports multiple storage adapters (ActiveStorage, Shrine, Paperclip, Carrierwave, and ActionText) and implements lazy loading for model configurations to improve startup performance and prevent race conditions during initialization. Users will experience more robust configuration handling, better support for modern Rails file storage solutions, and faster application boot times.
_lib/rails\admin/config · high confidence
RailsAdmin helper and form builder refactoring
The RailsAdmin helpers have been reorganized into dedicated modules (ApplicationHelper, MainHelper) and a new FormBuilder class, introducing cleaner separation of concerns for navigation, breadcrumbs, and form rendering. This change adds support for composite primary keys via custom hidden field handling, improves logout path resolution with Devise scope detection and fallbacks, and enhances security by adding rel='noopener noreferrer' to external links and sanitizing object labels to prevent XSS. Users will see more robust form layouts with better error handling, consistent breadcrumb navigation, and improved compatibility with modern Rails features like composite keys and strict parameter handling.
_app/helpers/rails\admin · high confidence
Refactored action configuration and added Turbo Drive support
The action configuration system has been restructured to use a modular base class with explicit instance options, introducing a new \turbo?\ option (defaulting to true) to control navigation behavior for Turbo Drive. This change also updates the default response format for the Show action to HTML and ensures that the New action correctly handles object creation by sanitizing parameters and applying authorization attributes before saving.
_lib/rails\admin/config/actions · high confidence
Refactored field configuration into a modular class hierarchy
The field configuration system has been restructured to use a class-based hierarchy, introducing dedicated field types such as Association, SingularAssociation, and CollectionAssociation, along with a new Group container for organizing fields in edit views. This change replaces the previous hash-based configuration approach with explicit classes that handle specific behaviors like dynamic scoping, filtering, and nested forms, providing a more consistent and maintainable way to configure how data is displayed and edited in the admin interface.
_lib/rails\admin/config/fields · high confidence
Refactored section configuration classes and added list view options
The section configuration classes in lib/rails\_admin/config/sections have been reorganized: a new Base class provides shared configuration (including fields, groups, and description support) for all sections, while specific sections (List, Show, Edit, Create, Update, Export, Modal, Nested) now inherit from Base or Edit as appropriate. The List section now exposes configurable options for checkboxes, filters, items per page, limited pagination, search fields, search help text, sorting, model scopes, and row CSS classes.
_lib/rails\admin/config/sections · high confidence
Refactored support modules for asset resolution, CSV export, and datetime handling
The \lib/rails\_admin/support\ directory has been restructured into dedicated modules to improve maintainability and functionality. \AssetSource\ now centralizes the resolution of the \config.asset\_source\ setting, handling deprecation warnings for Webpack/Importmap and auto-detecting Propshaft or Sprockets. \CSVConverter\ has been rewritten to use Rails' native CSV library, supporting schema-based field selection, association exports, and configurable encodings with BOM handling. \Datetime\ provides a robust translation layer between Ruby strftime formats and Flatpickr, while \CompositeKeysSerializer\ ensures safe serialization of ActiveRecord composite primary keys. Additionally, \HashHelper\ offers recursive symbolization for configuration hashes.
_lib/rails\admin/support · high confidence
Removal of RailsAdmin environment configuration files
The environment-specific configuration files for the RailsAdmin application (development.rb, production.rb, and test.rb) have been removed. This change accompanies the migration of RailsAdmin into a gem and Rails 3 Engine, meaning these environment settings are no longer managed directly within this directory and are instead handled by the engine's internal structure or the host application.
config/environments · high confidence
Removal of default Rails welcome page
The default 'Welcome aboard' static landing page (public/index.html) has been removed from the application. Users will no longer see the standard Ruby on Rails placeholder content when visiting the root URL; instead, the application will serve whatever route or controller action is configured as the default entry point.
public · high confidence
Removal of legacy Rails 3 script and seed files
The \db/seeds.rb\ file, previously used to populate the database with default values via \rake db:seed\, has been removed. Additionally, the \script/rails\ executable, which served as the entry point for running Rails commands in older setups, has been deleted. These changes reflect the migration of the rails\_admin application into a gem and a Rails 3 Engine, eliminating the need for these legacy local scripts.
db, script · medium confidence
Removed legacy Prototype and script.aculo.us JavaScript libraries
The application has removed the bundled client-side dependencies Prototype (v1.7\_rc2) and script.aculo.us (v1.8.3), including their core modules (effects, controls, dragdrop) and the Rails UJS adapter (rails.js). This change eliminates the legacy JavaScript framework stack that previously handled AJAX requests, form submissions, and UI effects, requiring the application to rely on alternative mechanisms for these client-side interactions.
public/javascripts · high confidence
Ship prebuilt RailsAdmin assets to eliminate client-side build steps
RailsAdmin now ships with precompiled JavaScript and CSS assets (rails\_admin.js and rails\_admin.css) in app/assets/builds, allowing applications to use the gem without configuring a JavaScript build pipeline like Propshaft, Sprockets, or importmap. A new bin/build.js script handles this compilation using esbuild and sass, ensuring the output is kept in sync with source files under src/.
bin · high confidence
Ship prebuilt asset bundle and refresh SimpleMDE editors
The application now serves a prebuilt, minified CSS bundle for Rails Admin (app/assets/builds/rails\_admin.css) instead of generating styles on the fly, which includes an update to Font Awesome 6.7.2. Additionally, the interface ensures that SimpleMDE rich-text editors are properly refreshed when their containing tab is shown, and editors are flushed before modal submissions to guarantee data integrity.
app/assets · high confidence
Simplified Rails Admin generator templates for modern asset pipelines
The generator templates have been updated to support modern JavaScript and CSS asset pipelines. The initializer template now includes commented-out configuration blocks for CanCanCan and Pundit authorization, PaperTrail auditing, and Gravatar integration, providing a cleaner starting point. Additionally, new template files for JavaScript (rails\_admin.js) and SCSS (rails\_admin.scss.erb) have been added to facilitate integration with Webpacker, Importmap, and other asset management systems, replacing the previous tight coupling with legacy asset structures.
_lib/generators/rails\admin/templates · high confidence
Simplified RailsAdmin installation generator with explicit asset source handling
The RailsAdmin installation generator has been rewritten to simplify the setup process and remove tight legacy integrations with Devise and specific JavaScript bundlers. The generator now defaults to shipping a prebuilt asset bundle and requires users to explicitly specify the asset delivery method (propshaft, sprockets, or external) via the --asset flag. It no longer auto-detects or supports Webpacker, Vite, Importmap, or jsbundling as direct asset sources; instead, these environments are treated as 'external', requiring the user to manually wire the provided JavaScript and SCSS entrypoints into their build scripts. The generator also skips route addition if the engine is already mounted and handles initializer configuration more robustly.
_lib/generators/rails\admin · high confidence
Test coverage
Add test coverage for dummy\_app configuration and setup scripts; Add test support helpers for Cuprite, autocomplete, and rich text editors; Added Mongoid dummy app models for integration testing; Added ORM specification files for ActiveRecord and Mongoid; Added adapter-specific test suites for ActiveRecord and Mongoid; Added comprehensive test suite for RailsAdmin core components; Added controller specs for RailsAdmin application and main controllers; Added dummy Taggable concerns for Active Record and Mongoid specs; Added dummy application database schema and seed data; Added environment configuration files for the DummyApp test suite; Added integration tests for JavaScript widgets; Added integration tests for PaperTrail auditing and CanCanCan/Pundit authorization adapters; Added integration tests for layout and core RailsAdmin features; Added shared test suites for adapter conformance and field type behavior; Added test controller files to the dummy application; Added test coverage for Comment::Confirmed scope; Added test coverage for Mongoid nested class scope syntax; Added test coverage for Rails Admin field types; Added test coverage for RailsAdmin configuration components; Added test coverage for RailsAdmin helper methods; Added test coverage for RailsAdmin support utilities; Added test coverage for association field behaviors and base field validation logic; Added test fixtures for Dragonfly and Paperclip asset storage; Added test fixtures for dummy application jobs; Added test fixtures for namespaced polymorphic associations; Added test hooks for RailsAdmin head customization; Added test to verify eager loading behavior; Added test view template for Player show page; Added tests for ActiveRecord adapter association and property handling; Added tests for CanCanCan and PaperTrail extension adapters; Added tests for Mongoid adapter associations, properties, and repository; Added tests for Rails Admin action configuration and visibility logic; Added tests for Rails Admin period criteria handling; Added tests for User::Confirmed model in Mongoid; Added tests for list section field ordering; Comprehensive integration test suite for admin actions; Expanded ActiveRecord test fixtures for Rails 7.1+ and file uploads; Expanded dummy app schema for comprehensive test coverage; Integration test coverage for admin fields; Moved dummy\_app documentation to spec directory; Removal of legacy test infrastructure files; Updated dummy app asset pipeline configuration; Updated dummy app initializers for Rails 5+ compatibility and ORM switching; Updated dummy app layout for modern asset pipeline; Updated test dummy app error pages and assets; Updated test infrastructure with FactoryBot, Cuprite, and external asset support.
Dependencies
Expanded CI matrix with new Rails and Mongoid versions
The gemfile-based test matrix has been updated to include support for Rails 7.1, 7.2, 8.0, and 8.1, as well as Mongoid 9. A new gemfile specifically for testing the composite\_primary\_keys gem has been added. These changes ensure the library is validated against the latest major versions of its core dependencies during continuous integration.
gemfiles · high confidence
RailsAdmin 4.0 dependency overhaul and prebuilt asset bundle
RailsAdmin 4.0 now ships a prebuilt JavaScript and CSS bundle, removing the need for a build step in Propshaft or Sprockets applications and dropping support for Webpacker and Vite asset sources. The gemspec has been updated to require Ruby \>= 2.7 and Rails \>= 7.0, while the JavaScript dependencies have been modernized to include Bootstrap 5, Hotwired Turbo, and Flatpickr. The dummy application has been upgraded to Rails 7.0 and now uses esbuild and Sass for its own asset pipeline.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 44 → 47 (+3.5)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 57 → 61 (+3.6)
- Architecture 97 → 54 (-42.5)
- Maturity 59 → 63 (+3.5)
- Readiness 22 → 73 (+51.2)
- Security 76 → 85 (+8.7)
- Accessibility 33 (new)
Resolved (32)
- (anonymous) (cognitive 32) (src/rails_admin/widgets.js)
- Change coupling: ui.js ↔ widgets.js (src/rails_admin/ui.js)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 12 more
New (61)
- (anonymous) (cognitive 17) (src/rails_admin/ui.js)
- (anonymous) (cognitive 21) (src/rails_admin/remote-form.js)
- (anonymous) (cognitive 36) (src/rails_admin/filtering-select.js)
- (anonymous) (cognitive 88) (src/rails_admin/widgets.js)
- (anonymous) (cyclomatic 28) (src/rails_admin/filtering-select.js)
- (anonymous) (cyclomatic 29) (src/rails_admin/filtering-multiselect.js)
- (anonymous) (cyclomatic 36) (src/rails_admin/widgets.js)
- (anonymous)::_query (cognitive 23) (src/rails_admin/filtering-multiselect.js)
- (anonymous)::append (cognitive 30) (src/rails_admin/filter-box.js)
- (anonymous)::append (cyclomatic 32) (src/rails_admin/filter-box.js)
- Ambiguous naming overlap. ApplicationController.get_model() returns an AbstractModel instance, while AbstractModel.model() also returns the underlying ActiveRecord/Mongoid model class. The name get_model in the controller is misleading as it doesn't return a 'model' in the Rails sense (the class), but rather the 'abstract model' wrapper. This creates confusion about what 'model' refers to in different contexts.
- ApplicationHelper.menu_for (cognitive 16) (app/helpers/rails_admin/application_helper.rb)
- Change coupling clique: belongs_to_association.rb, has_many_association.rb, has_one_association.rb (lib/rails_admin/config/fields/types/belongs_to_association.rb)
- Documentation: no architecture or design documentation (docs/actions.md)
- Duplicate exception types with ambiguous distinction. In the context of an admin panel, 'Model' and 'Object' are often used interchangeably to refer to the record being accessed. Having two separate exception types for what is likely the same error condition (record not found) creates unnecessary complexity for error handling.
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 41 more
Changes since last survey
- 44 commits — 40 feature/other, 4 fixes
By area
- (root) — 14 commits
- lib/rails_admin — 6 commits
- spec/dummy_app — 5 commits
- spec/integration — 4 commits
- app/views — 2 commits
- spec/rails_admin — 2 commits
- vendor/assets — 2 commits
- (repo) — 1 commit
- .github/workflows — 1 commit
- app/helpers — 1 commit
- docs/README.md — 1 commit
- docs/actiontext.md — 1 commit
- docs/add-custom-css-and-js-assets.md — 1 commit
- spec/spec_helper.rb — 1 commit
- spec/support — 1 commit
- src/rails_admin — 1 commit
Notable commits
- fix: Fix _discard leaking into SQL for multi-select enum filters (#3738)
- fix: Fix malformed rubocop directive comment
- fix: Fix the viewport meta tag's name attribute
- fix: Revert npm package.json version ahead of actual publish
- change: Ask whether an enum is null, not whether it equals ''
- change: CI: install ImageMagick against a refreshed package list
- change: Change default response format of the show action to HTML (#3705)
- change: Drop Proc bounds from a field's length validation
- change: Drop support for Rails 6.x and Ruby 2.5/2.6
- change: Drop the docs left behind by the asset rework
- change: Drop the dummy app's tooling for asset modes that no longer exist
- change: Filter ferrum 0.18's console stack-frame log lines
- change: Flush rich-text editors before the modal submits
- change: Fully specify all ESM imports with an extension (#3749)
- change: Keep one dead browser from failing the examples after it
- change: Keep the dummy app's cookies readable, and cover CSRF both ways
- change: Keep the dummy app's test hooks out of development
- change: Let any callable serve as asset_source, and show what it is for
- change: Let associated_collection_scope decide the order it asks for
- change: Let the page catch up before reading the database
- …and 24 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
railsadminteam/rails_admin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fca081f27abd6d5e76efbe4906dddd3c0b0382a2 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.