Skip to content
CAI
Software that uses CAICheck a score

rom-rb/rom

54.6

Adequate · 22 September 2026

13k

lines of production code

Ruby

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Ruby-based Object-Relational Mapping (ORM) library that provides a structured API for defining and executing data transformations and persistence operations. It features a modular architecture with separate components for core logic, repository management, and declarative changesets, supporting both SQL and in-memory backends. The system enables developers to manage database associations, automate timestamp injection, and perform complex data mapping through a composable pipeline interface.

Features

Add Relation\#changeset method for creating and updating records

The ROM library now includes a new \Relation\#changeset\ method, allowing users to create, update, or delete records via a changeset interface. This method supports predefined types (create, update, delete) as well as custom changeset classes, enabling more flexible data manipulation workflows directly on relation objects.

changeset/lib/rom/plugins/relation · high confidence

Add SQL and Upsert example scripts

Added two new example scripts to demonstrate ROM repository usage. The first, sql.rb, shows basic create, update, and delete operations using a SQLite in-memory database. The second, upsert.rb, demonstrates a custom upsert command for handling unique constraints on tags, along with association management between books and tags in a PostgreSQL environment.

repository/examples · high confidence

Add instrumentation and registry reader plugins for relations

The ROM library introduces two new plugins for the relation component: an Instrumentation plugin that allows external systems like dry-monitor or ActiveSupport::Notifications to track relation operations, and a RegistryReader plugin that enables relations to access other relations through a shared registry. These changes provide new capabilities for monitoring and cross-relation access.

core/lib/rom/plugins/relation · high confidence

Add new bin scripts for development and documentation

Three new executable scripts are added to the bin directory to improve the developer experience. bin/bundle automates running bundle install across the core, repository, and changeset subdirectories. bin/console provides an interactive Ruby environment with a pre-configured ROM SQL setup, including database schema creation for books, users, and tasks, along with repository and context classes for easier exploration. bin/doc runs yard documentation generation for the core, mapper, and repository directories. The console script uses IRB instead of Pry and includes associations for tasks and books.

bin · high confidence

Added ROM repository benchmarks

Added benchmark scripts in the repository/benchmarks directory to measure the performance of ROM repository operations (create, update, delete) against Sequel and ActiveRecord, and to compare ROM commands versus changesets.

repository/benchmarks · high confidence

Added new benchmarking suite for ROM and ActiveRecord

A new set of benchmarking scripts has been added to the core/benchmarks directory, providing performance comparisons between ROM and ActiveRecord. The suite includes basic benchmarks for loading users, posts, and tasks with various associations, as well as profiling scripts for specific query patterns. The setup script now supports optional seeding via the SEED environment variable, allowing users to control whether the database is populated with test data before running the benchmarks.

core/benchmarks · high confidence

Added placeholder for repository log directory

A new empty directory named 'log' has been added to the repository, containing a '.gitkeep' file. This ensures the directory is tracked by version control, allowing developers to store log files or other data in this location without the directory being ignored or removed by git.

repository/log · high confidence

Automatic timestamp and datestamp injection for commands

Commands can now automatically populate timestamp and datestamp attributes when executed. The new \:timestamps\ plugin allows specifying which attributes should be set to the current UTC time, while the \:datestamps\ plugin sets attributes to the current date. This is configured via \timestamps\ and \datestamps\ class methods on command classes, enabling automatic time tracking without manual intervention in the command logic.

core/lib/rom/plugins/command · high confidence

Establish core project scaffolding and configuration

The core directory now includes essential project configuration files: \.rspec\ for RSpec test runner settings, \.simplecov\ for code coverage, \.yardopts\ for documentation generation, a \Guardfile\ for automated testing and linting, a \Rakefile\ for build tasks, and standard \README.md\ and \LICENSE\ files. These changes provide the necessary infrastructure for testing, documentation, and continuous integration within the core module.

core · high confidence

Extracted rom-changeset into a standalone gem

The changeset functionality has been extracted from rom-repository into a separate, standalone gem. This includes the creation of a dedicated directory structure with its own Rakefile, .rspec configuration, and documentation files (README, CHANGELOG, LICENSE). The CHANGELOG indicates that changesets are no longer coupled to repositories and now use relations to retrieve their commands, making the component more modular and independently maintainable.

changeset · high confidence

Initial project structure and tooling configuration

The repository was initialized with a comprehensive set of configuration files to support development, testing, and documentation. This includes a Rakefile to manage spec tasks for core, repository, and changeset components, alongside .rspec and .simplecov for test execution and coverage. Development tooling is configured via .rubocop.yml and Gemfile.devtools (including RuboCop 1.69.2). Documentation generation is set up with .yardopts and .inch.yml, while CI/CD and code quality are handled by .codeclimate.yml. The project also includes a Docker environment (Dockerfile, docker-compose.yml, docker\_start.sh) for consistent development, along with standard metadata files like LICENSE, CONTRIBUTING.md, and a detailed CHANGELOG.md.

(repo-wide) · high confidence

Introduce ROM Changeset API for declarative data transformation

The changeset library now provides a structured API for defining and executing data transformations. Users can create stateful changesets (Create, Update, Delete) that support composable mapping pipelines via the new \map\ and \extend\ methods, allowing custom data transformations and diff calculations. The API includes support for associated changesets to handle nested data structures, and a pipe registry for reusable transformation steps. This enables more flexible and declarative data handling in ROM.

changeset/lib · high confidence

Introduce core association and command infrastructure

The core library now includes a complete, internalized framework for managing database associations and command execution. This change introduces new classes for defining association types (OneToOne, OneToMany, ManyToOne, ManyToMany, and their 'through' variants) and their corresponding definition objects, allowing the core to handle relation linking logic previously managed elsewhere. Additionally, the command system is restructured with a new \CommandCompiler\ and \CommandRegistry\ that automatically generate and cache command instances for relations, supporting complex graph-based command execution and result mapping. These additions provide the foundational building blocks for the ORM's data loading and persistence operations.

core/lib · high confidence

Introduce new ROM::Repository class hierarchy and session support

The repository library has been restructured into a new class hierarchy: ROM::Repository serves as the abstract base, with ROM::Repository::Root providing a specialized implementation for working with a root relation. The update adds support for database transactions via the new ROM::Repository::Session class, which allows batching multiple changesets and committing them together. Additionally, the class interface now supports defining commands with custom mappers and plugins, and the relation reader is memoized for performance.

repository/lib · high confidence

Removals

Removed Session module and version file

The Session module, which previously managed object states (inserts, updates, removes) and provided methods like \#commit, \#update, and \#new?, has been removed from the codebase. Additionally, the lib/session/version.rb file containing the version constant has been deleted.

lib · high confidence

Behavioural changes

Added placeholder for core/log directory

A .gitkeep file was added to the core/log directory, ensuring the directory is tracked by version control even when empty.

core/log · low confidence

Repository module reorganized with updated changelog and configuration files

The repository module has been reorganized, moving ROM repository files into a dedicated subdirectory. This change includes the addition of configuration files such as .rspec, .simplecov, and .yardopts, alongside an updated CHANGELOG.md that documents the removal of the Repository::Root\#aggregate method in favor of Relation\#combine. The module also includes updated README and LICENSE files, and a Rakefile for running tests and linting.

repository · high confidence

Test coverage

Add shared test fixtures and examples for core/spec/shared; Add unit tests for ROM Relation class interface; Add unit tests for ROM::Relation methods; Added integration tests for create, delete, and update commands; Added integration tests for gateway parameter handling; Added integration tests for relation features; Added integration tests for repository features; Added integration tests for the changeset plugin and command options; Added integration tests for the mapper DSL; Added shared test fixtures for repository specs; Added test fixtures for commands, mappers, and relations; Added test support utilities for constant leak detection, schema definition, and type configuration; Added tests for ROM::Setup auto-registration behavior; Added tests for memory repository linting and relation instrumentation; Added tests for the schema timestamps plugin; Added unit tests for ROM Changeset components; Added unit tests for ROM association classes; Added unit tests for ROM command plugins; Added unit tests for ROM::Attribute behavior; Added unit tests for ROM::Processor::Transproc; Added unit tests for ROM::Relation::Wrap\#combine; Added unit tests for ROM::Schema methods; Added unit tests for core ROM components; Added unit tests for repository and session behavior; Added unit tests for the in-memory ROM backend; Extracted shared test fixtures for the changeset feature; Refactor test environment and remove obsolete spike tests; Refactored test configuration and environment setup; Standardize test environment configuration for Ruby 3.4 and coverage; Updated integration tests for ROM setup and schema configuration; Updated test helper for Ruby 3.4 and coverage support.

Dependencies

ROM library version updated to 5.4.3

The ROM library has been updated to version 5.4.3, as reflected in the version file. This change updates the internal version constant to reflect the new release.

lib/rom · high confidence

Update ROM gem dependencies to version 5.4

The ROM gem and its sub-components (rom-core, rom-repository, rom-changeset) have been updated to depend on version 5.4. This change aligns the dependency graph with the 5.4 release cycle, ensuring compatibility with the latest stable versions of dry-\* and transproc libraries.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 51 → 55 (+3.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (+0.6)
  • Architecture 100 → 94 (-5.3)
  • Maturity 50 → 51 (+1.2)
  • Readiness 38 → 43 (+4.7)
  • Security 48 → 65 (+16.7)

Resolved (16)

  • Change coupling: command.rb ↔ builder.rb (core/lib/rom/configuration_dsl/command.rb)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_7 (Dockerfile)
  • No exposed public API
  • Test reliability not included

New (44)

  • Documentation: no installation or build instructions (README.md)
  • FixmeComment (core/lib/rom/data_proxy.rb)
  • Floating git dependency: dry-initializer
  • Floating git dependency: rom-sql
  • Floating git dependency: transproc
  • High CVE: [GHSA redacted] (Gemfile)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 24 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rom-rb/rom was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7cdb1a2be9b2a71a27c1e912b7942455b4c4dec3 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.