cognitedata/oryx
59.2
Adequate · 24 September 2026
1.3k
lines of production code
F#
primary language
5
measurements over time
What this system is
Oryx is a high-performance, functional HTTP client library for F\# that utilizes a composable middleware pipeline to manage requests and responses. It provides core capabilities for logging, metrics, error handling, and concurrent execution, while offering dedicated extensions for serializing and deserializing data using System.Text.Json, Newtonsoft.Json, Protobuf, and Thoth.Json.Net.
Features
Add Newtonsoft.Json and Protobuf serialization extensions
The Oryx framework now includes dedicated extensions for serializing and deserializing HTTP responses using Newtonsoft.Json and Google.Protobuf. For JSON, the \Oryx.NewtonsoftJson\ module provides a \ResponseReader\ to decode responses into strongly-typed results and a \JsonPushStreamContent\ type to efficiently stream JSON data directly to the output. Similarly, the \Oryx.Protobuf\ module offers a \ResponseReader\ for Protobuf decoding and a \ProtobufPushStreamContent\ type for streaming Protobuf payloads, enabling users to handle these specific content types natively within the Oryx HTTP pipeline.
extensions/Oryx.NewtonsoftJson · high confidence
Initial release of Oryx HTTP client library
Introduces the Oryx library, a functional HTTP client for F\# that uses a composable middleware pipeline. The library provides core abstractions for HTTP requests and responses, including support for form-urlencoded content, configurable logging via ILogger, and metrics collection. It features error-handling middleware such as \catch\, \choose\, and \protect\, along with utilities for sequential and concurrent handler execution, caching, and chunking.
src · high confidence
Initial release of Oryx v1 with Apache 2.0 license and solution structure
This change introduces the initial v1 release of Oryx, a high-performance .NET cross-platform functional HTTP request handler library for F\#. The diff establishes the project's foundational structure, including the \oryx.sln\ solution file which defines the core \Oryx\ library, \Tests\, JSON/Protobuf extension projects, and example applications. It adds the Apache 2.0 \LICENSE\, a \CODE\_OF\_CONDUCT\, and a \CODEOWNERS\ file to govern contributions. The release also includes a \.editorconfig\ for code formatting, a \renovate.json\ for dependency management, and a \test.sh\ script for running tests with coverage. The \README.md\ is updated to provide installation instructions, usage examples, and documentation for the HTTP handler pipeline, logging, and content handling features.
(repo-wide) · high confidence
Introduce Oryx.ThothJsonNet extension for JSON serialization
A new extension library, Oryx.ThothJsonNet, has been added to provide JSON handling capabilities built on top of Thoth.Json.Net and Oryx. This library introduces specific encoders for handling 64-bit integers (int64) as JSON numbers rather than strings, supports URI encoding, and provides utilities for property bags and optional properties. It also includes a custom HttpContent implementation (JsonPushStreamContent) for streaming JSON responses and a response reader that maps JSON decoding errors to a specific exception type, ensuring consistent error handling for API consumers.
extensions/Oryx.ThothJsonNet · high confidence
Introduces System.Text.Json support for Oryx
The Oryx extension library now supports the .NET System.Text.Json serializer, providing a new \JsonPushStreamContent\ type for streaming JSON responses and a \ResponseReader\ module for deserializing JSON responses. This allows users to leverage the modern System.Text.Json API within the Oryx HTTP client pipeline.
extensions/Oryx.SystemTextJson · high confidence
New Oryx HTTP client examples for GitHub and WikiSearch
Added two new F\# example projects demonstrating the Oryx HTTP client library. The GitHub example shows how to fetch and decode a single JSON field (release tag) using Thoth.Json.Net, while the WikiSearch example demonstrates querying the Wikipedia API and decoding a list of search results. Both examples include project configuration files and dependency references for Oryx and Thoth.Json.Net.
examples · high confidence
Test coverage
Initial test suite for Oryx HTTP client
Added a new test project under the \test/\ directory to verify the Oryx HTTP client library. The suite includes unit and property-based tests covering the task builder integration, context manipulation (headers, tokens, HTTP clients), HTTP fetch operations (GET/POST with logging and metrics), and handler logic (sequential, concurrent, error handling, and panics).
test · high confidence
Dependencies
Oryx extensions and examples updated to .NET 8
The Oryx extensions (Oryx.NewtonsoftJson, Oryx.Protobuf, Oryx.SystemTextJson, Oryx.ThothJsonNet) and example projects (GitHub, WikiSearch) now target .NET 8, replacing previous framework versions. This update aligns the library's ecosystem with the latest .NET runtime, ensuring compatibility and access to modern .NET features for users integrating Oryx into their applications.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 53 → 59 (+6.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 95 (new)
- Architecture 100 → 89 (-11.0)
- Maturity 41 → 49 (+7.4)
- Readiness 54 → 48 (-5.1)
- Security 64 → 87 (+23.0)
Resolved (12)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Test reliability not included
- Unpinned build actions
- complexity unreadable for .fs — churn × complexity hotspots could not be measured
- dormant codebase — no living knowledge left to concentrate
New (9)
- Duplicated block (10–12 lines × 2) (src/HttpHandler.fs)
- Duplicated block (12 lines × 2) (src/HttpHandler.fs)
- Duplicated block (17 lines × 2) (extensions/Oryx.NewtonsoftJson/JsonPushStreamContent.fs)
- High secret: WD-SECRET-0001 (strong_name.snk)
- High: security finding (details withheld)
- Leaked secret: private-key-blob (strong_name.snk)
- Medium: security finding (details withheld)
- Scattered collaborators
- TooManyFunctions: HttpHandler (src/HttpHandler.fs)
Changes since last survey
- 4 commits — 3 feature/other, 1 fixes
By area
- .github/workflows — 2 commits
- (root) — 1 commit
- .config/dotnet-tools.json — 1 commit
Notable commits
- fix: fix(security): Pin GitHub Actions to digests (#186)
- change: Use Cognite Renovate config instead of config:base (#184)
- change: chore(deps): update dependency dotnet-sdk to v8.0.425 (#187)
- change: chore(deps): update dependency fantomas to v7.0.6 (#185)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
cognitedata/oryx was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fdcd3ecdd6a935b13cb1f191035365e4af627295 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.