Skip to content
CAI
Software that uses CAICheck a score

Shopify/shipit-engine

48.5

Weak · 19 September 2026

10.3k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Shipit is a Rails engine that automates software deployment and release management for GitHub repositories. It provides a web interface and API for managing stacks, triggering deploys and rollbacks, and monitoring task execution in real time. The system supports advanced workflows such as merge queues, continuous delivery scheduling, and automated review stack provisioning via GitHub webhooks.

How it got here

2014–2015 — Engine restructuring and feature expansion

28 changes.

The project refactored the application into a Rails engine, upgrading its dependencies to modern Ruby and Rails versions while establishing a robust test infrastructure. This period also introduced significant new features, including multi-organization GitHub support, continuous delivery scheduling, and enhanced frontend capabilities for task monitoring and deployment control.

2016 — Engine isolation and API expansion

17 changes.

Shipit was refactored into an isolated Rails engine, restructuring controllers, models, and background jobs to improve modularity and reliability. This period introduced comprehensive new API endpoints for stack and deployment management, alongside features like merge queues, continuous delivery scheduling, and granular API client permissions. The work also included significant UI overhauls for stacks, deploys, and tasks, enhancing visibility and safety controls for deployment workflows.

2017–2026 — Review stacks and merge queue integration

16 changes.

This period focused on implementing core review stack provisioning logic, including webhook handlers and repository management UI, alongside the introduction of a merge queue workflow. The work also expanded system capabilities with a browser extension, API client management, and CCMenu feed support, while significantly increasing test coverage and refactoring task execution strategies.

Features

Add CCMenu project XML feed endpoint

Shipit now provides a project.xml builder view that generates a CCMenu-compatible XML feed for the current stack. This feed exposes the build status (mapped from merge status), activity state (Building or Sleeping), last build timestamp and label, and the web URL, allowing external CI monitoring tools to track the stack's deployment status.

app/views/shipit/ccmenu · high confidence

Add CI build script with multi-database and Rails 7.1.1 setup testing

A new \script/cibuild\ script has been added to automate continuous integration tasks. It supports running the test suite against MySQL, PostgreSQL, and SQLite3 databases, as well as executing Rubocop for code style checks. Additionally, it includes a 'setup' mode that installs Rails 7.1.1 and runs the project's template against a new application, skipping specific components like Action Cable, Turbolinks, and Active Storage to validate the setup process.

script · high confidence

Add UI for managing API clients

Users can now create, view, and manage API clients through a new interface. The index page lists existing clients with pagination, the new client form allows selecting specific permissions from a checklist, and the show page displays the authentication token and provides a form to update permissions.

_app/views/shipit/api\clients · high confidence

Add vendor libraries for keyboard shortcuts, desktop notifications, and list virtualization

This change introduces several new vendor JavaScript libraries to support new product capabilities. It adds Mousetrap v1.5.3 along with a global-bind extension, enabling keyboard shortcuts (such as Cmd+F) to function even when focus is inside text input fields. It includes a jQuery-based notification plugin that wraps the browser Notification API, handling permission states and displaying desktop alerts. Additionally, it integrates Clusterize.js v0.16.0 with its associated CSS to virtualize long lists, improving page performance on large data sets by rendering only visible rows.

vendor · high confidence

Initial release of the Shipit browser extension

This change introduces the Shipit browser extension, adding the core source files for Chrome, Firefox, and Safari support. The extension injects an iframe into GitHub repository pages to display merge status from the Shipit service, dynamically resizing the view and visually adjusting merge buttons based on queue status and build results. It includes the necessary HTML, CSS, and JavaScript assets, along with the Safari-specific Info.plist configuration.

contrib/browser-extension · high confidence

Introduce client-side merge status polling and task output streaming

The application now includes a new \MergeStatusPoller\ that periodically checks the server for merge queue status updates and refreshes the page content via AJAX, while a new \task.js\ module exposes an \OutputStream\ stream to the global window object. This stream allows plugins and the UI to listen for real-time task status changes and output chunks, enabling features like live task filtering and dynamic status updates on the client side without full page reloads.

app/assets/javascripts · high confidence

Introduce review stack provisioning and repository management UI

This change adds the foundational infrastructure and user interface for managing review stacks. It introduces a \ProvisioningHandler\ framework (including a base class and an unregistered handler that blocks transitions for missing configurations) to support dynamic stack provisioning logic. On the user-facing side, it adds a complete set of views for repository management, including listing, creating, and editing repository settings (such as enabling review stacks and configuring provisioning behaviors like 'Allow All' or 'Allow With Label'). It also provides a dedicated view for displaying and managing stacks associated with a repository, including options to view archived stacks.

_app/models/shipit/provisioning\handler, app/views/shipit/repositories · high confidence

Introduces new model classes for deployment logic, user handling, and configuration

This change adds a suite of new model classes to the Shipit application to support updated deployment workflows and configuration management. Key additions include AnonymousUser and CommandLineUser to handle unauthenticated or CLI-based access, DeploySpec and TaskDefinition to manage deployment configurations and task variables, and CommitChecks to handle continuous integration status tracking. The update also introduces UndeployedCommit for managing commit deployment states, DeployStats for tracking deployment metrics, and Duration for parsing time intervals. Additionally, new classes like ProvisioningHandler, ReviewStackProvisioningQueue, and Webhooks support review stack provisioning and webhook event handling, while UnlimitedApiClient and GithubStatus provide API and status integration capabilities.

app/models/shipit · high confidence

New Shipit API endpoints for stack management, deployments, and CI integration

This change introduces a comprehensive set of new API controllers under the Shipit API namespace, enabling programmatic management of stacks and their lifecycle. Users can now create, update, and delete stacks (including archive/unarchive states), trigger and abort tasks, and manage merge requests. The API supports triggering deploys and rollbacks with options for concurrency and environment variables, while also allowing the reporting of release statuses (success/failure). Additionally, it provides endpoints to list commits (with undeployed filtering), view deploy history, manage webhooks (renamed to use delivery\_url), and access CCMenu-style XML status feeds for continuous integration monitoring.

app/controllers/shipit/api · high confidence

New custom validators for ASCII-only and subset constraints

Two new custom ActiveModel validators have been added to the application: \AsciiOnlyValidator\ and \SubsetValidator\. The \AsciiOnlyValidator\ ensures that specific record attributes contain only ASCII characters, rejecting any non-ASCII input. The \SubsetValidator\ allows validation that a given attribute's value is a subset of a specified superset defined via the \:of\ option. These tools enable stricter data integrity checks for fields requiring specific character sets or predefined value ranges.

app/validators · high confidence

New deployment and release validation snippets for Python, Ruby, and Lerna

Added a suite of executable snippets in lib/snippets to support version validation and publishing for Python eggs, Ruby gems, and Lerna monorepos. The new assert-\* scripts verify that git tags match the current HEAD and that package versions align with their respective manifests (setup.py, gemspec, package.json, or lerna.json). Publishing workflows now include release-gem for Ruby gems (with allowed\_push\_host enforcement), publish-lerna-independent-packages for Lerna (supporting from-git and from-package mechanisms), and push-to-heroku for Heroku deployments (including database migration checks and rollback on failure). Additional utilities like fetch-gem-version, generate-local-npmrc, and git-askpass streamline credential handling and version detection.

lib/snippets · high confidence

New frontend features for deploy control, search, and configuration

This update introduces several new interactive capabilities to the Shipit interface. Users can now configure continuous delivery schedules with a 'copy to all' feature to replicate time settings across days, and deploy actions require acknowledging a checkbox before proceeding. A new 'Abort and Rollback' button allows users to cancel and reverse deployments directly from the log. Additionally, repository and stack search interfaces now support keyboard navigation (arrow keys and Enter) for faster selection, while commit locking and release status updates are handled via inline AJAX interactions. The system also displays a dismissible warning when CI is ignored on a stack, persisting the dismissal in local storage.

app/assets/javascripts/shipit · high confidence

New rake tasks for scheduled operations, development simulation, and team management

This change introduces four new Rake task files in lib/tasks to support specific operational workflows. The cron.rake file defines scheduled jobs for minutely and hourly execution, including refreshing deployed revisions, scheduling continuous delivery, updating GitHub status, merging pull requests, reaping dead tasks, processing rollups, refreshing user data, and managing review stack caches and directories. The dev.rake file adds a stream task for developers to simulate deploy output by appending random text chunks to a deploy record. The shipit.rake file provides a deploy task that allows running a deployment from the command line by specifying a stack and revision. Finally, the teams.rake file adds a fetch task to import members from GitHub teams configured in the application settings.

lib/tasks · high confidence

Review Stacks webhook handlers for Pull Requests

This change introduces a new set of webhook handlers for GitHub Pull Request events (opened, closed, edited, reopened, labeled, unlabeled, and assigned) to support the Review Stacks feature. These handlers manage the lifecycle of review stacks by creating, archiving, and unarchiving them based on repository provisioning settings and label changes. Specifically, opening a PR can trigger stack creation, while closing a PR archives the stack. Label changes (adding or removing a specific provisioning label) can trigger archiving or unarchiving depending on the repository's configuration (allow/prevent with label). Reopening a PR unarchives the stack. The handlers also capture PR labels and update PR metadata.

_app/models/shipit/webhooks/handlers/pull\request · high confidence

Shipit engine converted to an isolated Rails engine with new API and merge queue capabilities

The Shipit codebase has been refactored into an isolated Rails engine, introducing a new API authentication system via \Shipit::Api::BaseController\ and \Shipit::ApiClient\ models that support granular permissions (read, write, deploy, lock). This change also adds a merge queue feature, including a \Shipit::MergeStatusController\ for handling merge requests and a \Shipit::ContinuousDeliverySchedule\ model to manage deployment time windows. Additionally, the engine now supports GitHub Check Runs via the \Shipit::CheckRun\ model and integrates with the GitHub Deployment API through \Shipit::CommitDeployment\ and \Shipit::CommitDeploymentStatus\.

shipit-engine · high confidence

Shipit engine now supports multiple GitHub organizations

The Shipit engine has been updated to support configuration and interaction with multiple GitHub organizations, moving beyond the previous single-organization constraint. This change introduces new configuration methods such as \github\_organizations\ and \github\_default\_organization\ within the \Shipit\ module, allowing the system to manage distinct GitHub App configurations per organization. The \github\ method now accepts an optional organization parameter to retrieve the correct configuration, ensuring that API interactions and webhook handling are scoped to the specific organization context.

lib · high confidence

Shipit restructured as an isolated engine with new API client and merge queue capabilities

Shipit has been converted into an isolated Rails engine, reorganizing the application controllers into a modular structure under app/controllers/shipit. This change introduces a new API client management system (ApiClientsController) that allows users to create and manage API tokens with specific permissions, and adds a dedicated CCMenu URL endpoint for CI integration. The platform now supports a merge queue feature via the MergeRequestsController, enabling teams to queue and manage pull request merges. Additionally, the update includes a continuous delivery scheduling interface (ContinuousDeliverySchedulesController) for configuring deployment windows, commit locking controls (CommitsController), and enhanced GitHub App webhook handling with signature verification in WebhooksController.

app/controllers/shipit · high confidence

Removals

Removed database seed file

The db/seeds.rb file has been deleted, meaning the application no longer provides a default script to populate the database with initial seed data via the db:seed command.

db · high confidence

Behavioural changes

API serialization overhaul with conditional attributes and new entity support

The API response structure for stacks, commits, tasks, and users has been updated to support new capabilities and cleaner data exposure. Users will now see \deploy\_spec\, \branch\, \merge\_queue\_enabled\, \locked\_since\, and \ignore\_ci\ fields in stack payloads, alongside \started\_at\, \ended\_at\, \action\, and \description\ in task payloads. The API now exposes \github\_id\ on user objects and introduces dedicated serializers for anonymous users and command-line access. Additionally, the system now supports conditional attribute inclusion via a new \ConditionalAttributes\ concern, allowing fields like \lock\_reason\ or \pull\_request\ to be omitted when not applicable, and introduces \ReviewStackSerializer\ to expose review stack data linked to pull requests.

app/serializers · high confidence

Background jobs refactored into isolated engine with improved reliability

The background jobs in the Shipit engine have been restructured to inherit from a new \BackgroundJob\ base class that standardizes retry logic for GitHub API errors (including Octokit rate limits and authentication failures) and enforces configurable execution timeouts. This change introduces deduplication locks to prevent concurrent execution of the same job, adds specific handling for continuous delivery scheduling and stack destruction batching, and updates the last-deployed reference creation to use the correct \refs/heads/\ prefix.

app/jobs/shipit · high confidence

Configurable duplicate job handling in background jobs

Background jobs now support a configurable strategy for handling concurrent executions of the same job. A new Unique module introduces a ConcurrentJobError when a lock timeout occurs, and allows jobs to specify whether duplicate jobs should be retried or dropped via the on\_duplicate setting, giving users control over how race conditions are managed.

_app/jobs/shipit/background\job · high confidence

Database schema evolution and migration updates

This location contains the database migration files that define the application's data structure and its evolution over time. The changes include the initial baseline schema creation, the introduction of new capabilities such as pull request tracking, merge queues, and review stacks, and the addition of new tables for commit deployments, check runs, and continuous delivery schedules. It also covers behavioral adjustments like allowing optional task commits, enabling task retries, and supporting commit locking. Furthermore, it includes structural refactors such as renaming the pull\_requests table to merge\_requests, elevating the repository concept, and upgrading various github\_id columns to bigint to support larger identifiers.

db/migrate · high confidence

Deferred parent record updates via background job

The application now defers updating parent records (touching) to a background job instead of doing it synchronously during the transaction. A new \Shipit::DeferredTouch\ concern collects these updates in Redis and processes them asynchronously via \DeferredTouchJob\, which improves performance by batching updates and respecting \ActiveRecord::NoTouching\ settings.

app/models/concerns · high confidence

The status display components now prevent navigation when a target URL is not provided. Links associated with statuses that lack a \target\_url\ are rendered as disabled, ensuring users cannot click through to non-existent destinations.

app/views/shipit/statuses · high confidence

Introduces blocking status logic to shipit status checks

A new common module for shipit statuses now includes a blocking? method, allowing specific status checks to prevent a merge if they are not successful. This change enables the system to enforce blocking statuses based on the commit's configuration, ensuring that critical failures halt the merge process.

app/models/shipit/status · high confidence

Merge status UI and merge queue integration

The merge status display has been updated to support a merge queue workflow. When a merge queue is enabled, users can now add or remove pull requests from the queue via new UI buttons, and status messages (such as 'backlogged' or 'success') provide specific guidance on queue actions. The interface also displays a warning when a stack contains a large number of commits, encouraging users to rebase into smaller, atomic changes.

_app/views/shipit/merge\status · high confidence

Migration of secret key configuration and addition of CCMenu inflection

The application no longer defines the secret\_key\_base in the deleted config/initializers/secret\_token.rb file, indicating a move to a different configuration method (likely config/secrets.yml or environment variables). Additionally, the inflections initializer now explicitly defines 'CCMenu' as an acronym, ensuring consistent capitalization for this term throughout the application.

config/initializers · high confidence

Migration to CSS native variables and new stylesheet structure

The application's main stylesheet has been replaced with a new file (shipit.css.erb) that utilizes native CSS custom properties (variables) for theming and includes specific styles for tooltips and accessibility. This change reflects the removal of the SASS preprocessor dependency, shifting the styling approach to standard CSS with ERB templating.

app/assets/stylesheets · high confidence

New GitHub webhook handlers for check suites, team membership, pushes, and statuses

Shipit now processes four new GitHub webhook events directly through dedicated handler classes located in the autoloader path. Push events now update only active (non-archived) stacks by syncing GitHub data for the specific branch. Check suite events trigger refreshes of check runs for commits on matching branches. Team membership changes (add/remove) are handled by syncing team members to the local user database. Commit status events are processed to create or update status records on corresponding commits.

app/models/shipit/webhooks · high confidence

New layout templates and head partial for Shipit and merge status pages

The application now uses dedicated layout templates for the main Shipit interface and the merge status page. The Shipit layout (\shipit.html.erb\) displays the configured application name in the page title, includes the stack environment, renders a favicon, and features a dismissable banner for enabling desktop notifications as well as a GitHub status banner that shows operational issues and their details. The merge status layout (\merge\_status.html.erb\) supports a mode parameter for dark/light themes and whitelists specific GitHub CDN domains for stylesheets. A new partial \\_head.html.erb\ has been added to the layouts directory to support shared head content.

app/views/layouts · high confidence

New settings validation UI and variable input support

Shipit now provides a dedicated missing settings page that checks for and displays the status of GitHub App configuration, Redis, and Host settings, helping users identify and fix missing configuration before shipping. Additionally, the variables form now supports select dropdowns with default options and allows URL parameter overrides for task values, improving flexibility in task configuration.

app/views/shipit · high confidence

New task execution and output UI with concurrency controls

The Shipit interface now includes dedicated views for managing and monitoring tasks. Users can view a paginated list of past tasks, initiate new tasks via a form that displays the execution steps and allows setting environment variables, and monitor live output. The output view features a search filter for logs, a link to raw text output, and an abort button that optionally triggers a rollback to a specific short commit SHA. Concurrency is enforced: if a task definition does not explicitly allow it, the UI prevents starting a new task while another is active, showing a warning instead. The task list also indicates if safeties were ignored during execution.

app/views/shipit/tasks · high confidence

Rails application restructured as an engine with expanded API and stack management routes

The application configuration has been refactored to run as a Rails Engine rather than a standalone application, removing legacy boot and database configuration files in favor of new example secrets files for development and Shopify-specific environments. The routing layer has been significantly expanded to support a comprehensive API namespace for managing stacks, deploys, rollbacks, tasks, and merge requests, alongside new web routes for stack settings, commit check tailing, and merge status management.

config · high confidence

Redesigned commit display with locking and deployment status

The commit list UI has been updated to provide clearer context and control over individual commits. Users can now see which commits are expected to be deployed next, view detailed author information with avatars, and see code change counts (additions/deletions) only when they exist. A new locking mechanism allows users to lock or unlock commits directly from the list, with tooltips and confirmation dialogs to prevent accidental changes. The layout has been restructured to use separate DOM elements for actions and details, improving consistency and performance through fragment caching.

app/views/shipit/commits · high confidence

Redesigned deploy creation and management interface

The deploy workflow has been overhauled to improve safety and visibility. Creating or rolling back a deploy now requires explicit acknowledgment via a checklist and, if another deploy is active, a mandatory confirmation checkbox to prevent concurrent deployments. The interface displays clearer commit summaries, including author avatars and GitHub links, and highlights commits excluded from the current deploy. Deploy status cards now show task duration, code change stats, and indicators for ignored safeties or aborts. Additionally, users can view monitoring panels and, if enabled, validate or reject release statuses directly from the deploy view.

app/views/shipit/deploys · high confidence

Redesigned stack management UI with new configuration and monitoring views

The stack interface has been overhauled to provide better visibility and control. A new Settings page allows users to configure continuous deployment schedules, enable merge queues, and manage stack archival. The main stack view now displays prominent banners for CI misconfigurations, deployment locks, and continuous delivery delays. Additionally, new dedicated pages have been added to view deployment statistics, manage custom tasks, and inspect commit checks, while the header navigation has been updated to include these new sections and support arbitrary host-defined links.

app/views/shipit/stacks · high confidence

Refactor API controller concerns into isolated modules

The API controller logic in app/controllers/concerns/shipit/api has been reorganized into three distinct modules: Cacheable, Paginable, and Rendering. The Cacheable concern now handles HTTP caching headers (ETag and Last-Modified) for resource rendering. The Paginable concern centralizes pagination configuration (default and max page sizes, ordering) and injects Link headers for pagination navigation. The Rendering concern standardizes the JSON response structure, including handling for destroyed resources (204 No Content) and validation errors (422 Unprocessable Entity). This refactoring improves code modularity and separation of concerns within the API layer.

app/controllers/concerns/shipit/api · high confidence

Refactor and consolidate UI helper logic in app/helpers

The application's view helper logic has been reorganized into distinct, isolated modules (ApiClientsHelper, ChunksHelper, DeploysHelper, GithubUrlHelper, MergeStatusHelper, ShipitHelper, StacksHelper, and TasksHelper). This change introduces specific behavioral updates: API client tokens are now masked after five minutes for security; deploy and redeploy buttons now display clearer captions and tooltips based on safety bypass states and commit limits; deployment status text is corrected (e.g., 'Timed out' instead of 'Timedout'); and commit messages now render GitHub emojis. Additionally, helper methods for rendering GitHub URLs, pull request links, and monitoring panels have been centralized to improve consistency and maintainability.

app/helpers · high confidence

Refactor authentication logic and introduce pagination support

The authentication mechanism has been extracted into a dedicated \Shipit::Authentication\ concern, which now enforces GitHub authentication via a \force\_github\_authentication\ before\_action. This change introduces a new behavior where users requiring a fresh login are automatically logged out and redirected to GitHub, while unauthorized users receive a 403 Forbidden response listing the required GitHub teams. Additionally, a \Shipit::Pagination\ concern is introduced to standardize list handling with configurable default and maximum page sizes, and a patch for ActiveModelSerializers is added to resolve namespace issues in the serializer logic.

app/controllers/concerns/shipit · high confidence

Refactor task execution into a strategy pattern with monotonic timing and dry-run support

The task execution logic has been restructured into a strategy pattern, introducing a \Base\ class and a \Default\ implementation to manage how tasks are run. This change introduces a dry-run mode (triggered by the \SHIPIT\_DRY\_RUN\ environment variable) that skips actual deploy steps while still logging commands. Task timing now uses the monotonic clock for more accurate duration reporting, and the checkout process includes logic to fetch specific commits if the initial fetch fails. Additionally, command output now rounds the 'finished in' duration to three decimal places.

_app/models/shipit/task\_execution\strategy · high confidence

Refactored deploy spec into modular discovery components

The deploy specification logic has been restructured into a set of isolated, composable modules (Bundler, Capistrano, Kubernetes, Lerna, NPM, PyPI, and Rubygems) that are included in the main FileSystem-based DeploySpec. This change replaces the previous monolithic implementation with a chain-of-responsibility pattern where each module handles discovery for its specific technology stack (e.g., detecting Gemfile for Bundler, package.json for NPM, or lerna.json for Lerna) and provides the appropriate dependency installation, deployment, and rollback steps. Users benefit from cleaner configuration inheritance, more robust handling of specific package managers (such as enforcing publishConfig for NPM or supporting Lerna independent versions), and extensible task discovery that respects the machine's directory and environment settings.

_app/models/shipit/deploy\spec · high confidence

Removal of development environment configuration

The specific configuration file for the development environment (config/environments/development.rb) has been removed from the application. This file previously defined settings such as disabling class caching, disabling eager loading, enabling local error reports, and configuring asset debugging. Its removal means these explicit development-specific overrides are no longer present in this location, likely relying on default Rails behavior or configuration defined elsewhere.

config/environments · high confidence

Shipit engine upgraded to version 0.45.4

The Shipit engine has been updated to version 0.45.4. This release includes a new CastValue module for boolean serialization, a refactored Command class with improved environment variable handling and timeout support, and a new SameSiteCookieMiddleware to enhance cookie security. Additionally, the GitHubApp logic has been consolidated to handle authentication and API interactions, and the engine now supports GitHub Enterprise configurations via dedicated API and web endpoints.

lib/shipit · high confidence

Shipit-engine now requires Ruby 3.1+ and Rails 8.0+ with updated development tooling

Shipit-engine has raised its minimum runtime requirements to Ruby 3.1 and Rails 8.0, enforced via the new \template.rb\ installer and \.ruby-version\ file (set to 3.4.9). The project has also introduced a new \.rubocop.yml\ configuration targeting Ruby 3.2, which disables several legacy style and metrics cops (such as \Metrics/ClassLength\ and \Style/StringLiterals\) and excludes specific engine files from line-length checks. Additionally, the \Rakefile\ has been refactored to use the standard Rails engine rake tasks and includes a RuboCop rake task, while \.gitignore\ has been expanded to cover dummy app artifacts and configuration files.

(repo-wide) · high confidence

Task output rendering refactored with search, filtering, and performance improvements

The task output view now supports real-time search and filtering of log lines, with search queries persisted in the URL fragment for easy sharing. A new search bar component handles keyboard shortcuts (Cmd/Ctrl+F) and debounced input updates. To handle large logs efficiently, the rendering engine integrates Clusterize.js for virtualized scrolling, significantly improving performance on huge output pages. Additionally, ANSI escape sequences are stripped before filtering to ensure accurate text matching, and plugin errors are now rescued to prevent them from breaking the entire UI.

app/assets/javascripts/task · high confidence

Updated Rails binstubs and added bootstrap script

The Rails binstubs (bin/rails, bin/rake, bin/rubocop) have been updated to use Bundler's standard generated wrappers, which ensures they correctly resolve dependencies from the Gemfile. Additionally, a new bin/bootstrap script was added to streamline the development environment setup by copying profile-specific secrets, installing dependencies, and initializing the database schema and seed data.

bin · high confidence

Test coverage

Added Rails dummy application for engine testing; Added controller tests for Shipit API endpoints; Added model tests for deployment, commit, and hook logic; Added test coverage for Shipit API controllers; Added test coverage for Shipit model behaviors; Added test coverage for background jobs in test/jobs; Added tests for Pull Request webhook handlers; Added tests for SameSite cookie middleware behavior; Added tests for Shipit::DeploySpec::FileSystem config loading and inheritance; Added tests for deploy/task commands, provisioning handlers, and pull request serialization; Added tests for job retry logic and continuous delivery scheduling; Added unit tests for core Shipit components; Establishes test infrastructure with command timeout verification; New test helper modules for API, hooks, JSON, and query assertions.

Dependencies

Shipit Engine upgraded to Rails 8.1 and Ruby 3.2

The Shipit Engine gem has been upgraded to require Ruby 3.2.0 or higher and Rails 8.1.1 or higher. This update replaces the previous Rails 4.0.3 dependency with the latest Rails 8.1.2 stack, bringing modern framework features and security fixes. The gemspec and Gemfile have been updated to reflect these new version constraints, along with adjustments to development and test dependencies such as Rubocop and Webmock.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 48.

Lenses

  • Code Health 96
  • Architecture 91
  • Maturity 53
  • Readiness 54
  • Security 38
  • Domain Modelling 66
  • Accessibility 60

Changes since last survey

  • 300 commits — 277 feature/other, 23 fixes

By area

  • (repo) — 107 commits
  • (root) — 96 commits
  • app/models — 27 commits
  • app/jobs — 15 commits
  • lib/shipit — 12 commits
  • app/controllers — 8 commits
  • app/views — 6 commits
  • test/models — 5 commits
  • .github/workflows — 4 commits
  • db/migrate — 3 commits
  • app/helpers — 2 commits
  • docs/setup.md — 2 commits
  • lib/shipit.rb — 2 commits
  • test/controllers — 2 commits
  • test/dummy — 2 commits
  • test/unit — 2 commits
  • .github/probots.yml — 1 commit
  • app/assets — 1 commit
  • bin/bootstrap — 1 commit
  • test/jobs — 1 commit

Notable commits

  • fix: Add changelog entry for the Clusterize CSP spacer-height fix
  • fix: Fix commit status
  • fix: Fix dev up by removing isogun. Add a check for whether dev bootstrap has been run. Can successfully run tests locally.
  • fix: Fix failing setup ruby 2.7 step in some Github Actions
  • fix: Fix rubocop multiline method call indentation
  • fix: Fix stack deletion take two
  • fix: Fix tests for paginate check runs refresh
  • fix: Merge pull request #1271 from Shopify/emit-lock-hook-after-revert
  • fix: Merge pull request #1343 from Shopify/revert-1341-kwb/split-check-runs-and-statuses-jobs-into-multiple
  • fix: Merge pull request #1377 from Shopify/fix-stack-deletion-take-two
  • fix: Merge pull request #1424 from Shopify/fix-commit-status
  • fix: Merge pull request #1440 from Shopify/simonyc/fix-local-github-auth-problem
  • fix: Merge pull request #1448 from Shopify/gulkaran/fix-bundler-frozen-flag
  • fix: Merge pull request #1456 from Shopify/tdickers/fix-dev-up
  • fix: Merge pull request #1484 from Shopify/edilsonacjr/fix-removal-of-all-permissions
  • fix: Merge pull request #1500 from brianwarsing/changelog/csp-clusterize-fix
  • fix: Revert "Make RefreshCheckRunsJob and RefreshStatusesJob enqueue one of themselves per commit"
  • fix: Revert "Release 0.40.1"
  • fix: Revert "Restrict to Rails 7.1.1"
  • fix: Shopify local dev fixes
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Shopify/shipit-engine was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 44e0ea7fe8e62be6a7610e062586853675890765 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.