gazay/gon
68.3
Adequate · 19 September 2026
743
lines of production code
Ruby
with JavaScript
1
measurement over time
What this system is
This system is a Ruby gem that injects server-side variables into JavaScript views for Rails applications. It provides a secure, request-scoped mechanism to expose data to the client side, featuring support for Jbuilder and RABL templates. The library also includes a client-side watch module that allows JavaScript to monitor these variables via AJAX polling.
How it got here
2011 — Architectural refactor and security hardening
5 changes.
The project underwent a major architectural refactor, shifting Gon from a module-based structure to a class-based, request-scoped architecture to ensure thread safety and prevent variable leakage. This period also focused on security hardening by adding Content Security Policy support and addressing [CVE redacted], alongside modernizing dependencies and introducing RuboCop for code style enforcement.
2012 — Gon engine refactoring and watch feature
3 changes.
The Gon rendering engine was refactored to support advanced configuration options, including AMD compatibility, CSP nonce injection, and thread-safe variable management. A new JavaScript watch functionality was added to enable AJAX-based monitoring of Gon variables with configurable polling and cleanup. Comprehensive test suites were implemented to verify core behavior, security, and integration with template engines.
2013–2015 — Rails compatibility and Jbuilder integration
4 changes.
This period focused on enhancing the library's compatibility with older Rails versions and expanding its integration with Jbuilder templates. Key developments included standardizing the test environment, adding support for pre-3.2.1 Rails, and enabling access to Rails URL helpers within Jbuilder. Additionally, new CoffeeScript watch functions were introduced to improve background data fetching capabilities.
Features
Added CoffeeScript watch, unwatch, and unwatchAll functions
A new CoffeeScript implementation of the watch module has been added to the application. This introduces gon.watch to monitor variables via AJAX polling or one-time requests, supporting optional error callbacks for failed requests. It also provides gon.unwatch to stop monitoring a specific variable's callback and gon.unwatchAll to clear all active timers and reset the internal state, allowing users to manage background data fetching more effectively.
coffee · high confidence
Added JavaScript watch functionality for monitoring Gon variables
The JavaScript module now includes a new \watch.js\ file that enables monitoring of Gon variables via AJAX polling. Users can register watchers using \gon.watch\, which supports configurable intervals, custom callbacks, and error handling via a new \possibleErrorCallback\ parameter. The module also provides \gon.unwatch\ to stop specific watchers and \gon.unwatchAll\ to clear all active timers, ensuring proper cleanup of background polling tasks.
js · high confidence
New Jbuilder parser enables Rails URL helpers in templates
A new parser class has been added to the Jbuilder integration, allowing Jbuilder templates to access Rails URL helpers (such as \user\_path\) and controller helpers directly. This change modifies how the library parses Jbuilder source files by dynamically defining methods for available route helpers and controller helper methods, enabling more seamless integration with standard Rails view patterns within JSON templates.
lib/gon/jbuilder · high confidence
Behavioural changes
Add compatibility support for Rails versions prior to 3.2.1
A new compatibility layer for older Rails versions has been introduced in lib/gon/compatibility/old\_rails.rb. This file defines the Gon::ControllerHelpers module, which overrides the gon\_request\_uuid method to use SecureRandom.uuid instead of ActionDispatch::Request\#uuid, ensuring correct functionality on Rails versions below 3.2.1 where the native uuid method is unavailable.
lib/gon/compatibility · high confidence
Gon v7.1.0: Refactored architecture with request-scoped state and CSP support
This release introduces a major architectural refactor to improve thread safety and security. State storage has moved from Rails.cache to request-scoped storage using ActiveSupport::CurrentAttributes (with a fallback to RequestStore for older Rails versions), ensuring variables are isolated per request. The library now supports Content Security Policy (CSP) via nonce injection in inline scripts and enforces HTML entity escaping to address [CVE redacted]. Additionally, it adds a 'watch' feature for tracking variable changes, supports global variables, and includes updated Jbuilder and Rabl handlers with deprecation warnings for the old API.
lib/gon · high confidence
Introduce RuboCop linting and streamline test execution
The project now includes RuboCop for code style enforcement, configured with a gradual baseline via \.rubocop\_todo.yml\ and targeting Ruby 2.2. Test execution is simplified by adding a \.rspec\ file to automatically require the spec helper and updating the Rakefile to run RSpec specs as the default task.
(repo-wide) · high confidence
Refactored Gon into a modular class-based architecture with new integration features
The Gon library has been significantly refactored from a module-based structure into a class-based architecture, introducing dedicated modules for global variables (Gon::Global), request environment handling (Gon::EnvFinder), and variable watching (Gon::Watch). This change introduces new public APIs including \Gon.global\, \Gon.watch\, and a \push\ method for bulk variable assignment, while also adding native support for Jbuilder and RABL template handlers. The refactoring replaces the previous \Rails.cache\ storage mechanism with a request-scoped storage approach using \Gon::Current\ and \Gon::Request\, ensuring thread-safety and preventing variable leakage between requests, and includes compatibility shims for older Rails versions.
lib · high confidence
Refactored Gon rendering engine with new configuration options
The core rendering logic in lib/gon/base.rb has been rewritten to support a comprehensive set of configuration options, including AMD module compatibility, Content Security Policy (CSP) nonce injection, and global variable namespacing. Users can now control script tag attributes (type, cdata), enable automatic camelization of hash keys with configurable depth, and utilize a new 'watch' feature to automatically include dynamically added variables. The change also introduces a keys cache for improved performance and ensures thread safety by replacing Thread.current with RequestStore.
gon · high confidence
Test coverage
Added comprehensive test suite for Gon core, global, and helper functionality; Added test fixtures for jbuilder and rabl template rendering; Standardize test environment with spec\_helper.rb.
Dependencies
Update gem dependencies and modernize gemspec
The gemspec has been updated to declare explicit runtime dependencies on actionpack (\>= 3.0.20), activesupport, i18n (\>= 0.7), and multi\_json, while setting the minimum required Ruby version to 2.2.0. Development dependencies for testing and debugging (jbuilder, pry, pry-byebug, railties, rake, rspec \>= 3.0) are now explicitly listed. The Gemfile has been switched to use HTTPS and now conditionally pins concurrent-ruby, i18n, loofah, rabl, and request\_store to specific versions or includes them based on the target Rails version and Ruby version to ensure compatibility across different environments.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 68.
Lenses
- Code Health 100
- Architecture 69
- Maturity 59
- Readiness 72
- Security 97
Changes since last survey
- 300 commits — 256 feature/other, 44 fixes
By area
- (repo) — 92 commits
- (root) — 90 commits
- lib/gon — 57 commits
- spec/gon — 28 commits
- .github/workflows — 17 commits
- spec/spec_helper.rb — 7 commits
- lib/gon.rb — 4 commits
- coffee/watch.coffee — 3 commits
- .github/FUNDING.yml — 1 commit
- .github/dependabot.yml — 1 commit
Notable commits
- fix: Couple fixes in README
- fix: Fix CI issue
- fix: Fix a failure in thread_safe tests when using truffleruby
- fix: Fix a test failure with Rails8.1
- fix: Fix bug when using caching with 'rabl' gem.
- fix: Fix changelog links
- fix: Fix code highlighting in README
- fix: Fix deprecation warnings on view_path argument
- fix: Fix for jbuilder module.
- fix: Fix jbuilder specs
- fix: Fix keys cache
- fix: Fix kwargs usage for Ruby 2.7
- fix: Fix rabl specs
- fix: Fix rabl specs
- fix: Fix some errors
- fix: Fix specs
- fix: Fix specs
- fix: Fix specs for rabl rails
- fix: Fix tests
- fix: Fix using bare raise_error matcher
- …and 280 more
Architecture
- 0 containers · 1 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
gazay/gon was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 5ace42ad0c9aa173850721414db43e84680e7c8a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.