Skip to content
CAI
Software that uses CAICheck a score

jnunemaker/httparty

70.8

Strong · 26 September 2026

3.3k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

HTTParty is a Ruby library designed to simplify making HTTP requests, supporting standard methods like GET, POST, and PUT along with advanced features such as digest authentication, proxy configuration, and multipart file uploads. It provides built-in capabilities for parsing various response formats including JSON, XML, and CSV, while offering configurable logging and streaming support for efficient handling of large data transfers. The system includes a command-line interface for terminal-based HTTP interactions and ensures robustness through comprehensive testing suites and security measures like SSRF mitigation.

How it got here

2008 — HTTParty rebranding and modernization

14 changes.

The project rebranded from 'Web' to 'HTTParty', restructuring the codebase into a modular library with expanded HTTP method support and security fixes. This period involved migrating the build system away from legacy Hoe and Newgem scaffolding to a modern Gemfile-based workflow, while simultaneously updating the test suite to RSpec 3.1 and WebMock. Documentation, examples, and website assets were refreshed to reflect the new identity and capabilities of the library.

2009–2012 — CLI introduction and test infrastructure

6 changes.

This period focused on expanding HTTParty's usability by introducing a command-line interface for direct terminal usage. Significant effort was also dedicated to establishing a robust testing framework, including comprehensive Cucumber feature specifications, SSL verification infrastructure, and code organization improvements for response handling.

2013–2018 — Logging and streaming improvements

4 changes.

This period focused on enhancing HTTParty's observability and performance by introducing a configurable, extensible logging system with multiple output formats. Concurrently, the library refactored multipart form-data handling to support streaming large file uploads, significantly reducing memory usage and improving robustness for binary and special character data.

Features

Add configurable HTTP request/response logging with multiple output formats

HTTParty now includes a built-in logging system that allows users to log HTTP requests and responses in various formats. The library provides three built-in formatters: Apache-style combined log format, a curl-like verbose output showing headers and bodies, and a Logstash-compatible JSON format. Users can select a formatter via the \:logger\ option (e.g., \:curl\, \:apache\, or \:logstash\) and configure the log level. The system is extensible, allowing users to register custom formatters using \HTTParty::Logger.add\_formatter\.

lib/httparty/logger · high confidence

Initial website styling with reset and layout rules

Adds the common.css file which establishes the visual foundation for the website. It includes a YUI CSS reset to normalize browser defaults and defines specific styles for the page layout, including a centered wrapper, header, navigation, content area, and footer, along with typography and color settings for text elements.

website/css · high confidence

Introduce httparty command-line interface

Adds a new executable at bin/httparty that allows users to make HTTP requests directly from the terminal. The tool supports GET, POST, PUT, DELETE, HEAD, and OPTIONS verbs, and lets users specify request bodies, custom headers, and basic authentication. Output can be formatted as plain text, JSON, CSV, or XML, and includes a verbose mode for debugging and a --version flag.

bin · high confidence

New examples directory with comprehensive usage demonstrations

The \examples/\ directory has been added, providing a comprehensive set of Ruby scripts demonstrating how to use the library. These examples cover basic GET and POST requests, custom parsers (including XML with Crack and HTML with Nokogiri), basic authentication, multipart file uploads, streaming body downloads, logging configuration, international domain names (IDNs), and specific integrations for services like Amazon, Google, StackExchange, Twitter, and Microsoft Graph.

examples · high confidence

Standardize development environment with EditorConfig, RuboCop, and Guard

This change introduces configuration files to standardize the coding style and development workflow. An \.editorconfig\ file is added to enforce consistent indentation, line endings, and whitespace trimming across different editors and IDEs. A \.rubocop.yml\ configuration is introduced to define Ruby style rules, while a corresponding \.rubocop\_todo.yml\ file is generated to suppress existing offenses, allowing for incremental code cleanup. Additionally, a \Guardfile\ is added to automate running RSpec tests and Cucumber features on file changes, improving developer feedback loops.

(repo-wide) · high confidence

Removals

Removal of legacy deployment and website generation tasks

The project has removed several Rake tasks previously used for manual release management and website hosting. Specifically, the \deploy\, \local\_deploy\, \check\_version\, \install\_gem\_no\_doc\, and \manifest:refresh\ tasks in \tasks/deployment.rake\ are gone, as are the \ruby\_env\ environment task and the \website\_generate\, \website\_upload\, and \website\ tasks in \tasks/website.rake\. This indicates a shift away from the previous workflow that involved SVN tagging, direct gem installation, and rsync-based uploads to RubyForge, likely aligning with the move to the Echoe build system mentioned in the commit history.

tasks · high confidence

Removal of legacy website styling and rounded-corners script

The legacy website assets have been removed, specifically the \screen.css\ stylesheet that defined the site's visual theme (including the purple background, Georgia font, and specific color schemes for code and status indicators) and the \rounded\_corners\_lite.inc.js\ script (curvyCorners v1.2.9) used to render rounded corners on div elements. Users will no longer see the previous custom styling or JavaScript-based corner effects on the website.

website/javascripts, website/stylesheets · high confidence

Behavioural changes

Added release automation and removed legacy scaffolding scripts

The project now includes a new \script/release\ utility that automates the gem build, tagging, and publishing workflow, enforcing that releases originate from the main branch. Concurrently, several legacy scripts generated by the 'newgem' scaffolding tool (\script/console\, \script/generate\, \script/destroy\, and \script/txt2html\) have been removed, streamlining the development environment by eliminating obsolete code generation and documentation conversion tools.

script · high confidence

Extract HTTP response headers into a dedicated module

The HTTP response headers logic has been moved from the main response file into a new, standalone \lib/httparty/response/headers.rb\ file. This change improves code organization by isolating the header handling implementation, which now explicitly includes \Net::HTTPHeader\ and delegates to a hash structure, making the codebase easier to maintain and understand.

lib/httparty/response · high confidence

HTTParty 0.24.2 release with SSRF mitigation and new compression support

This release updates HTTParty to version 0.24.2 and introduces several behavioral changes and security improvements. It adds support for Brotli, LZW, and Zstandard decompression via the new Decompressor class, allowing users to handle these Content-Encoding types automatically. A critical security fix prevents Server-Side Request Forgery (SSRF) by validating that absolute URLs in redirects match the configured base\_uri. The library also now supports the HTTP MOVE, COPY, MKCOL, LOCK, and UNLOCK methods, and allows users to maintain the original HTTP method across redirects. Additionally, it improves digest authentication handling, supports SameSite cookie attributes, and allows custom URI adapters for international domain name support.

lib/httparty · high confidence

HTTParty library restructured and renamed from Web

The library has been renamed from 'Web' to 'HTTParty' and its codebase reorganized into a modular structure under the lib directory. The previous single-file implementation in lib/web.rb has been removed and replaced by lib/httparty.rb, which now serves as the main entry point. This change introduces a more robust feature set including support for HTTP methods like PATCH, HEAD, and OPTIONS, digest authentication, proxy configuration, streaming uploads, and customizable query string normalization, while removing the dependency on ActiveSupport.

lib · high confidence

Refactored multipart form-data handling with streaming support

Multipart request body generation has been refactored into a new \HTTParty::Request::Body\ class that supports streaming large file uploads via \HTTParty::Request::StreamingMultipartBody\ to reduce memory usage. The implementation now properly escapes filenames in the Content-Disposition header, forces binary encoding for file data, and rewinds files after reading. It also replaces the \mime-types\ gem with \mini\_mime\ for content type lookup and adds support for \ActionDispatch::Http::UploadedFile\ objects.

lib/httparty/request · high confidence

Removed legacy Hoe and Newgem build configuration files

The project has removed its legacy build configuration files, specifically \config/hoe.rb\ and \config/requirements.rb\. These files previously managed gem packaging and dependencies using the Hoe and Newgem tools. Their deletion indicates a migration away from these specific Ruby gem development frameworks, likely simplifying the build process or moving to a different gem management strategy.

config · medium confidence

Website content replaced with HTTParty documentation

The website files have been updated to display documentation for the HTTParty gem instead of the previous 'web' gem. The homepage now includes installation instructions, code examples for interacting with the Twitter API, and links to the project's GitHub repository and RubyForge page, replacing the old placeholder content and template files.

website · high confidence

Test coverage

Added SSL and stubbing test helpers; Added test coverage for HTTParty logger formatters; Added test fixtures for various data formats; Added tests for multipart body generation and streaming; Expanded test coverage for HTTParty core components; Migrated test suite to RSpec 3.1 and WebMock; New Cucumber feature specifications for HTTParty capabilities; New Cucumber step definitions for HTTParty testing; Updated SSL test fixtures with longer-lived certificates and larger keys.

Dependencies

Initial dependency manifest and gemspec setup

The project now uses a Gemfile and a formal gemspec to manage dependencies. The gemspec defines runtime requirements for 'csv', 'multi\_xml' (\>= 0.5.2), and 'mini\_mime' (\>= 1.0.0), and sets the minimum Ruby version to 2.7.0. The Gemfile includes development dependencies like 'guard' and test dependencies such as 'rspec' (\~\> 3.4), 'cucumber' (\~\> 2.3), and 'webmock'.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 52 → 71 (+18.8)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 96 (-3.1)
  • Architecture 96 → 100 (+4.4)
  • Maturity 59 → 56 (-3.5)
  • Readiness 33 → 80 (+46.5)
  • Security 63 → 82 (+19.3)

Resolved (17)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Test reliability not included

New (26)

  • ConnectionAdapter.attach_ssl_certificates (cognitive 25) (lib/httparty/connection_adapter.rb)
  • Documentation: no architecture or design documentation
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent parameter naming between module-level methods and class methods. Module methods use 'args' while class methods use 'path' and 'options'. This creates confusion about whether the first argument is a full URI or just a path segment, and obscures the fact that 'options' is the structured hash.
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Off-boarding risk: anonymized user #1
  • …and 6 more

Changes since last survey

  • 8 commits — 6 feature/other, 2 fixes

By area

  • (repo) — 4 commits
  • lib/httparty — 3 commits
  • spec/httparty — 1 commit

Notable commits

  • fix: Merge pull request #838 from robzolkos/fix-multi-xml-deprecation-warning
  • fix: fix: support JSON 3 parser options
  • change: Be less wasteful with Range used for raise_on A range such as 400..599 was turned into a 200 elements array, which was then turned into 200 strings and 200 regexes. Now it's more reasonable.
  • change: Merge pull request #827 from jnunemaker/dependabot/github_actions/actions/checkout-6
  • change: Merge pull request #843 from MaxLap/max_improve_raise_on
  • change: Merge pull request #846 from jnunemaker/codex/json-3-parser-compatibility
  • change: Preserve raise_on matcher compatibility
  • change: Test MultiXML constant selection

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jnunemaker/httparty was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9c238f85dd88fd77e7d9dcc77a81a3ef959ed499 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.