Skip to content
CAI
Software that uses CAICheck a score

lostisland/faraday

72.6

Strong · 26 September 2026

3.3k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Faraday HTTP client library for Ruby, providing a flexible and extensible framework for making HTTP requests. It supports multiple adapters, including a built-in test adapter for mocking, and offers middleware for authorization, JSON handling, logging, and error raising. The library features configurable parameter encoding, structured options management, and comprehensive utilities for handling headers and query parameters.

How it got here

2009–2010 — Repository modernization and test adapter

6 changes.

The project underwent significant repository modernization, replacing legacy tooling like Jeweler and test-unit with Bundler, RSpec, and Markdown documentation. Concurrently, the core library was initialized with default Net::HTTP configuration, and a new Test adapter was introduced to facilitate HTTP request mocking for unit testing.

2011–2018 — Core library consolidation and test suite creation

13 changes.

This period focused on integrating key middleware from the faraday\_middleware gem into the core Faraday library, including request and response handlers for JSON, authorization, and error handling. A comprehensive RSpec test suite was established to cover core components, utility classes, and shared adapter behaviors, ensuring robust coverage for the newly consolidated features.

2019–2020 — Configuration and logging refactoring

5 changes.

This period focused on restructuring Faraday's internal architecture by splitting monolithic options hashes and parameter encoders into dedicated, type-safe classes. It also introduced a customizable logging formatter for HTTP requests and responses, alongside comprehensive test coverage for the new components and the Test adapter.

Features

Initialize Faraday library with default Net::HTTP adapter and connection options

The main Faraday library file has been initialized to load core components (Connection, Middleware, Adapters, Utils) and establish a default configuration using the \:net\_http\ adapter. It provides a \Faraday.new\ method that merges user-provided options with \default\_connection\_options\, and exposes HTTP verb shortcuts (GET, POST, etc.) on the \Faraday\ module itself by forwarding calls to a lazily-initialized \default\_connection\. The library also sets \ignore\_env\_proxy\ to false by default and defines paths for autoloading.

lib · high confidence

Introduce case-insensitive HTTP headers and string-keyed params hashes

Added new utility classes \Faraday::Utils::Headers\ and \Faraday::Utils::ParamsHash\ to standardize how HTTP headers and query parameters are handled. \Headers\ provides a case-insensitive hash that preserves the original casing of header names and correctly parses raw HTTP header strings, while \ParamsHash\ ensures all parameter keys are consistently converted to strings for predictable lookups and serialization.

lib/faraday/utils · high confidence

Introduce customizable Faraday logging formatter

A new \Faraday::Logging::Formatter\ class is introduced to provide a structured and customizable way to log HTTP requests, responses, and errors. Users can now control which details are logged via options such as \headers\, \bodies\, and \errors\, and can specify the \log\_level\ for these entries. The formatter safely handles exceptions raised during the request cycle, preventing crashes when logging errors, and ensures body content is encoded to UTF-8. This replaces or supplements previous ad-hoc logging mechanisms with a consistent, inheritable interface.

lib/faraday/logging · high confidence

Introduces a new Test adapter for mocking HTTP requests

Adds a new \Faraday::Adapter::Test\ class that allows users to stub HTTP requests for testing purposes. This adapter supports defining matchers for various HTTP methods (GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS) using paths, regular expressions, or full URLs. It includes features such as strict mode for exact matching, support for Proc-based body validation, thread-safe stub management via a mutex, and utilities to clear stubs or verify that all expected calls were made.

lib/faraday/adapter · high confidence

New request middleware for Authorization, JSON, URL-encoded bodies, and instrumentation

This change introduces four new request middleware components to Faraday. The Authorization middleware now supports callable/proc-based credentials for dynamic token generation and ensures headers are not modified if already present. The JSON middleware allows for configurable encoders (including custom objects or array-based configurations) and handles boolean values correctly. The UrlEncoded middleware enables file objects as request bodies and respects the connection's params\_encoder option. Additionally, an Instrumentation middleware is added to measure request duration using ActiveSupport::Notifications or a custom instrumenter.

lib/faraday/request · high confidence

Behavioural changes

Modernized bin scripts for setup, testing, and console

The repository now provides updated shell scripts in the bin directory to streamline common development tasks. The new bin/setup script automates the installation of Bundler and project dependencies. The bin/test script has been consolidated to run both RuboCop linting and RSpec tests in a single step. Additionally, a new bin/console script is available to launch an IRB session with the gem's dependencies pre-loaded, facilitating easier experimentation.

bin · high confidence

Refactored options into dedicated, structured classes

The single, monolithic options hash has been split into distinct, type-safe classes: ConnectionOptions, RequestOptions, ProxyOptions, SSLOptions, and Env. This change introduces structured configuration for proxy settings (including automatic scheme defaults and empty-string handling), SSL/TLS parameters (such as SNI hostname support, verify\_hostname, and cipher lists), and request timeouts (separating read\_timeout from open\_timeout). Users benefit from clearer configuration APIs, better documentation via YARD, and improved thread safety by avoiding mutation of shared proxy option hashes.

lib/faraday/options · high confidence

Refactored parameter encoders into dedicated files with configurable sorting and array indexing

The parameter encoding logic has been split into two distinct modules: FlatParamsEncoder and NestedParamsEncoder. FlatParamsEncoder handles simple flat hashes where array values repeat the parameter key multiple times (e.g., \a=one&a=two\), while NestedParamsEncoder manages complex nested structures using bracket notation (e.g., \a\[b\]=1\). Both encoders now support configurable parameter sorting via a \sort\_params\ flag, which defaults to true to ensure consistent ordering for OAuth and caching. Additionally, NestedParamsEncoder introduces an \array\_indices\ option; when enabled, it includes numeric indices in array keys (e.g., \a\[0\]=1\) instead of empty brackets, and enforces a configurable \param\_depth\_limit\ to prevent excessive nesting.

lib/faraday/encoders · high confidence

Repository modernization and tooling cleanup

The repository has been modernized by removing legacy tooling and documentation formats: the Jeweler gem build system and RDoc support have been dropped in favor of Bundler and RSpec, the README has been converted from RDoc to Markdown, and the .document file has been removed. New configuration files have been added to standardize development practices, including .editorconfig for consistent formatting, .rspec for test runner defaults, .yardopts for documentation generation, and .cursorrules to provide AI assistant guidelines. Additionally, the LICENSE file was renamed to LICENSE.md, the copyright year was updated to 2026, and the .gitignore was expanded to exclude modern build artifacts and AI planning files.

(repo-wide) · high confidence

Response middleware moved to lib/faraday/response

The JSON, Logger, and RaiseError response middleware have been relocated from the faraday\_middleware gem into the core Faraday library under lib/faraday/response. This change makes these capabilities available directly in Faraday without requiring an external dependency, with the JSON middleware now supporting configurable decoders and the RaiseError middleware offering options to control request data inclusion and allowed status codes.

lib/faraday/response · high confidence

Test coverage

Added RSpec test suite and configuration for Faraday; Added example tests for the Faraday Test adapter; Added shared RSpec examples for adapter, params encoder, and request method testing; Added test coverage for Faraday options classes; Added test coverage for Faraday::Utils::Headers; Added test coverage for FlatParamsEncoder and NestedParamsEncoder; Added test coverage for JSON, Logger, and RaiseError response middleware; Added test coverage for core Faraday components; Added test coverage for request middleware components; Added test suite for the Test adapter; Added test support utilities for Faraday specs; Removed legacy test-unit test files.

Dependencies

Initialize Ruby and JavaScript dependency manifests

This change introduces the initial dependency configuration for the project by adding a Gemfile and faraday.gemspec for the Ruby library, and a package.json with package-lock.json for the documentation site. The Ruby side specifies a minimum Ruby version of 3.0, runtime dependencies on faraday-net\_http (\>= 2.0, \< 3.5), json, and logger, along with development and test dependencies including rack (\~\> 3.0), rspec (\~\> 3.7), webmock (\~\> 3.4), and RuboCop. The JavaScript side adds docsify-cli 5.0.0 as a dependency for serving the documentation.

(dependencies) · high confidence

Housekeeping

Faraday 2.14.4 release

This update bumps the library version to 2.14.4. The diff for lib/faraday shows the version constant updated in version.rb, with no other code changes in the provided excerpt.

lib/faraday · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 53 → 73 (+19.9)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 98 (-1.6)
  • Architecture 96 → 94 (-1.7)
  • Maturity 66 → 63 (-2.3)
  • Readiness 32 → 73 (+41.2)
  • Security 62 → 82 (+19.9)

Resolved (21)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • No exposed public API
  • No tests found
  • …and 1 more

New (21)

  • Confusingly similar method names for URL construction. build_url and build_exclusive_url likely serve similar but distinct purposes (one might merge params, the other might not or handle encoding differently), but the names do not clearly convey the difference. build_exclusive_url is particularly opaque.
  • Duplicated block (19 lines × 2) (lib/faraday/encoders/flat_params_encoder.rb)
  • FixmeComment (lib/faraday/encoders/nested_params_encoder.rb)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent access pattern for connection configuration. params and headers are exposed as direct properties (getter/setter), while other configuration like url_prefix has a setter url_prefix=(url, encoder) that takes extra arguments, and proxy has a setter proxy=(new_value). This creates an inconsistent API surface for configuring connection defaults.
  • Orphaned files with no living knowledge
  • Redundant and inconsistent naming for URL decoding operations. Similar to encoding, parse_query/parse_nested_query in Utils duplicates the intent of FlatParamsEncoder.decode. The naming convention is inconsistent (parse vs decode).
  • Redundant and inconsistent naming for URL encoding operations. EncodeMethods and FlatParamsEncoder appear to be legacy or internal implementations exposed publicly, while Utils exposes build_query and build_nested_query. The intent (encoding params to a query string) is duplicated across three different types with inconsistent method names (encode vs build_query).
  • Secret: aws-access-token (.travis.yml)
  • TodoComment (lib/faraday/adapter/test.rb)
  • TodoComment (lib/faraday/connection.rb)
  • TodoComment (spec/support/shared_examples/request_method.rb)
  • TodoComment (spec/support/shared_examples/request_method.rb)
  • TodoComment (spec/support/shared_examples/request_method.rb)
  • …and 1 more

Changes since last survey

  • 8 commits — 8 feature/other, 0 fixes

By area

  • lib/faraday — 4 commits
  • (root) — 1 commit
  • .github/workflows — 1 commit
  • lib/faraday.rb — 1 commit
  • spec/spec_helper.rb — 1 commit

Notable commits

  • change: Configure SimpleCov for 1.0, too
  • change: Define HTTP verb methods on Faraday so tools can see them
  • change: Document Options struct attributes for YARD
  • change: Keep Coveralls token out of pull request jobs
  • change: Preserve caller-owned JSON parser options
  • change: Support JSON 3 (#1687)
  • change: Update the local documentation server
  • change: v2.14.4

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

lostisland/faraday was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d37e1e0edd7761f6d8cb1cd722891490e6001a41 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.