Skip to content
CAI
Software that uses CAICheck a score

arsduo/koala

62.9

Adequate · 28 September 2026

2.2k

lines of production code

Ruby

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Koala is a Ruby gem that serves as a client library for the Facebook Platform, providing a unified interface for interacting with Facebook's Graph and REST APIs. It handles core social media operations including OAuth token management, batch API execution, real-time update subscriptions, and test user utilities. The system manages HTTP communication via Faraday, enforcing HTTPS by default and supporting complex request structures like file uploads and pagination.

How it got here

2010 — Initial scaffolding and API consolidation

5 changes.

This period established the foundational structure of the Koala gem, including project scaffolding, documentation, and community guidelines. It involved the removal of legacy Facebook Graph API client code and the introduction of a unified Ruby client library for Facebook's APIs. The work culminated in defining the core architecture with Faraday-based HTTP requests and a consolidated API interface.

2011–2017 — Test suite initialization and HTTP refactoring

8 changes.

This period focused on establishing a comprehensive RSpec test suite with fixtures and coverage tools to validate the library's core functionality. Concurrently, the HTTP service layer was refactored to enforce HTTPS by default and introduce dedicated request and response objects, improving security and code structure.

Features

Initial project scaffolding and documentation

This change establishes the foundational structure for the Koala gem by adding essential configuration and documentation files. It introduces a .gitignore to exclude build artifacts and IDE files, an .rspec file to enable randomized test execution, and .yardopts for documentation generation. It also adds standard repository metadata including a LICENSE, a Manifest of gem contents, a Rakefile for running specs, and a comprehensive changelog.md. Furthermore, it provides GitHub issue and pull request templates to guide community contributions, along with a Code of Conduct to define community standards.

(repo-wide) · high confidence

Initial release of the Koala Facebook API client library

Introduces the Koala gem, a Ruby client for the Facebook Platform. The library provides a unified API for interacting with Facebook's Graph and REST APIs, OAuth token management, real-time update subscriptions, and test user utilities. It defaults to using Faraday for HTTP requests and includes a configuration system for managing API credentials and HTTP options.

lib · high confidence

Removals

Removal of legacy Facebook Graph API client

The \src/facebook.rb\ file containing the \Facebook::GraphAPI\ class and its associated error handling has been deleted. This removes the built-in Net::HTTP-based client for interacting with the Facebook Graph API, including methods for fetching objects, managing connections, and posting to walls.

src · high confidence

Behavioural changes

Koala 3.7.0 release with unified API and configuration

This release introduces a unified \Koala::Facebook::API\ class that consolidates Graph API methods, replacing the previous separation of GraphAPI and RestAPI. It adds a global \Koala::Configuration\ object for managing settings like access tokens, app secrets, and rate limit hooks, and updates the HTTP service to use Faraday by default. The \Koala::Facebook::APIError\ class now exposes detailed error information including Facebook trace IDs and rate limit usage. Additionally, \TestUsers\ and \RealtimeUpdates\ are now standalone classes with improved initialization and validation, and the library version is bumped to 3.7.0.

lib/koala · high confidence

Refactored HTTP service with new request/response objects and HTTPS defaults

The HTTP service layer has been restructured to use dedicated \Request\ and \Response\ classes, standardizing how API calls are constructed and how responses are parsed. A key behavioral change is that HTTPS is now enforced by default for all requests, improving security out of the box. Additionally, the \UploadableIO\ component has been updated to accept \Tempfile\ objects directly, simplifying file upload handling in various frameworks.

_lib/koala/http\service · high confidence

Refactored batch API execution and pagination parsing

The batch API execution logic has been restructured to improve reliability and support for complex requests. Batch operations now explicitly handle access tokens and appsecret proofs for individual calls within a batch, ensuring correct authentication even when tokens differ. Pagination URL parsing has been updated to use the Addressable::URI library, fixing issues with non-encoded URLs returned by Facebook. Additionally, the batch API now supports recursive calls and better handles edge cases such as empty bodies or invalid JSON responses, while extracting error checking into a dedicated class for clearer error reporting.

lib/koala/api · high confidence

Test coverage

Added integration test for Graph Collections; Added test coverage for HTTPService Request and Response classes; Added test fixtures for OAuth, Graph API, and Batch API mocking; Added test support infrastructure and shared examples; Comprehensive test suite for Koala core components; Initialize RSpec test suite with coverage and configuration.

Dependencies

Koala 1.0 release with Ruby 2.1+ requirement and Faraday-based HTTP client

Koala 1.0 is now available, requiring Ruby 2.1 or higher. The library has switched its HTTP client from the deprecated Faraday-stack to Faraday and faraday-multipart, providing a more flexible and feature-rich connection layer. Runtime dependencies have been updated to include addressable, json (\>= 1.8), rexml, base64, ostruct, and cgi, while development and test dependencies now use RSpec 3.0, VCR, WebMock, and SimpleCov.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 64 → 63 (-1.5)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.0)
  • Architecture 100 → 74 (-26.4)
  • Maturity 49 → 49 (+0.0)
  • Readiness 67 → 70 (+2.4)
  • Security 81 → 85 (+4.9)

Resolved (1)

  • High: security finding (details withheld)

New (4)

  • Ambiguous naming for configuration access. configure likely sets global state, while config likely retrieves it. However, without signatures (getters/setters), it is unclear if config is a getter or a setter. If config is a setter, it duplicates configure. If it is a getter, the naming convention is inconsistent with typical Ruby idioms where config might imply the object itself rather than an action.
  • Inconsistent HTTP request abstraction. Koala.make_request takes raw parameters (path, args, verb, options) directly, while HTTPService.make_request expects a structured Request object. This forces users to either bypass the service layer or manually construct Request objects, creating a split in how HTTP calls are initiated.
  • Inconsistent pluralization vs singular naming for similar operations. While get_object vs get_objects is a common pattern, the presence of get_connection (singular) vs get_connections (plural, used in put_connections/delete_connections context) suggests a potential inconsistency in how single vs multiple resources are handled. Specifically, get_connection fetches a specific connection, but there is no get_connections to fetch multiple connections at once, whereas get_object/get_objects exists.
  • Redundant methods in Koala.Facebook.API. Both graph_call and api appear to perform the same HTTP request operation with identical signatures (minus post_processing on api, which might be optional or handled internally). This creates confusion about which method to use for standard API calls.

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • (root) — 1 commit

Notable commits

  • change: CI: Remove Code Climate coverage reporting (#706)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

arsduo/koala was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e3c47623880ab1d2b1c2df527de2aa993b40265e — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.