Skip to content
CAI
Software that uses CAICheck a score

octokit/octokit.rb

65.9

Adequate · 28 September 2026

10k

lines of production code

Ruby

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Octokit Ruby gem, a client library that provides programmatic access to the GitHub API and GitHub Enterprise Server management interfaces. It exposes modular clients for interacting with core GitHub resources, GitHub Actions, Apps, and Checks, while also offering specialized tools for enterprise administration and server configuration. The library handles authentication, HTTP request lifecycle management, and response parsing, serving as a comprehensive toolkit for developers and administrators to automate GitHub operations.

How it got here

2009–2011 — Octokit v10 refactor and GitHub Actions support

10 changes.

This period centered on a major architectural refactor of the Octokit library, transitioning to Faraday 2.x and splitting the client into modular components for improved maintainability and security. Concurrently, the project expanded its API coverage by introducing dedicated client modules for GitHub Actions, Apps, and Checks, accompanied by comprehensive RSpec test suites and fixture updates to ensure robust coverage.

2013–2024 — GitHub Enterprise and API expansion

10 changes.

This period focused on expanding the library's capabilities for GitHub Enterprise Server, introducing dedicated clients for administration and management tasks alongside comprehensive test coverage. It also included significant infrastructure improvements such as standardized release scripts, support for Faraday 2.x, and enhanced security measures like automatic redirect handling with credential dropping.

Features

Add GitHub Actions API client modules

New client modules have been added to manage GitHub Actions resources, including ActionsArtifacts for listing and deleting artifacts, ActionsSecrets for managing repository, organization, and environment secrets, ActionsWorkflowJobs for retrieving job details and logs, ActionsWorkflowRuns for listing, rerunning, canceling, and deleting workflow runs, and ActionsWorkflows for listing workflows and triggering dispatches. Additionally, new modules for the Apps API (apps.rb) and Checks API (checks.rb) provide methods for managing app installations, webhook deliveries, check runs, and check suites.

lib/octokit/client · high confidence

Expanded GitHub Enterprise Admin API coverage

The Enterprise Admin Client now exposes a broader set of administrative capabilities through dedicated modules. Users can manage user lifecycles (create, rename, delete, promote, demote, suspend, unsuspend) and impersonation tokens via the new Users module. Organization creation is available through the Orgs module. The License module provides access to enterprise license information. The Search Indexing module allows queuing of users, organizations, and repositories for indexing. Additionally, the AdminStats module offers granular statistics retrieval for repositories, hooks, pages, organizations, users, pull requests, issues, milestones, gists, and comments.

_lib/octokit/enterprise\_admin\client · high confidence

Introduce GitHub Enterprise Server Management API client

Adds a new \ManageGHESClient\ that enables programmatic management of GitHub Enterprise Server instances via the Manage API. Users can now configure maintenance modes, upload initial licenses (requiring the \faraday-multipart\ gem), apply configuration changes, retrieve enterprise settings, and manage authorized SSH keys. The client handles authentication using either basic auth or an API key for the root site admin, and automatically disables SSL verification when configured for self-hosted environments.

_lib/octokit/manage\_ghes\client · high confidence

New Rate Limit API with convenience methods

Users can now access detailed rate limit information via a new \Octokit::RateLimit\ struct, which exposes limit, remaining, resets\_at, and resets\in attributes. The library automatically parses these values from standard GitHub API headers (X-RateLimit-\) and also supports legacy response\_headers, ensuring compatibility with Enterprise instances that may not send rate limit headers. Convenience methods are provided to retrieve this data directly from API responses.

octokit · high confidence

Project initialization and development environment setup

The repository has been initialized with a new structure, replacing the legacy 'octopussy' gem with the 'Octokit' Ruby toolkit for the GitHub API. This change introduces a modern development workflow using Bundler and RSpec for testing, configured via a new \.rspec\ file and \Guardfile\ for automated test running. Code quality is enforced through RuboCop configuration (\.rubocop.yml\), and documentation generation is handled by YARD. The project also adopts standard open-source governance with the addition of a \CODE\_OF\_CONDUCT.md\, \CONTRIBUTING.md\, and \SECURITY.md\, while updating the \README.md\ to reflect the new installation and usage instructions.

(repo-wide) · high confidence

Standardized development and release scripts

The repository now includes a consistent set of shell scripts to streamline the developer workflow and release process. New scripts include \script/bootstrap\ for quiet dependency installation, \script/test\ for running specs with required environment variable checks, \script/console\ for launching an interactive shell, \script/guard\ for file watching, and \script/cibuild\ for CI integration. Additionally, \script/package\ handles gem building, \script/validate\ checks for insecure file permissions within the gem archive, and \script/release\ automates tagging, pushing, and publishing the gem to RubyGems.

script · high confidence

Behavioural changes

Automatic HTTP redirect following with cross-host authorization dropping

The Octokit client now automatically follows HTTP 301, 302, 303, and 307 redirects (up to a default limit of 3) for supported methods, transparently handling the request lifecycle without requiring explicit client configuration. A key behavioral change occurs when a redirect points to a different host: the middleware explicitly drops the Authorization header to prevent leaking authentication credentials to third-party domains, addressing a security concern where previous implementations might have retained credentials across hosts.

lib/octokit/middleware · high confidence

A monkey patch has been added to the Sawyer library to prevent global namespace pollution while correcting how SSH link relations are processed. This change ensures that when a link relation name is 'ssh', the system returns the raw href value instead of calling the standard super method, effectively working around an issue with malformed SSH URLs in GitHub API responses.

lib/ext · high confidence

Octokit Ruby gem v10.0.0: Major refactor and Faraday 2.x support

This release introduces a major architectural refactor of the Octokit client, splitting the monolithic client into modular components (Authentication, Connection, Configurable) and introducing dedicated clients for GitHub Enterprise Server (EnterpriseAdminClient, ManageGHESClient). The library now supports Faraday 2.x, adapting its middleware stack and authentication interfaces accordingly, while maintaining backward compatibility with older versions. Key behavioral changes include stricter repository URL validation, improved error handling with specific exception classes for various HTTP status codes, and enhanced security by masking sensitive credentials in client inspection output. The default API media type is set to v3, and the client now supports bearer token authentication and .netrc credential loading.

lib/octokit · high confidence

Support for Faraday 2.x and new feed parsing capability

The library now supports Faraday 2.x by introducing a compatibility layer (BaseMiddleware) that abstracts away the removal of Faraday::Response::Middleware in newer versions. Additionally, a new FeedParser middleware has been added to automatically parse RSS and Atom feed responses when the content-type indicates a feed, and the RaiseError middleware has been refactored to use this new base class for consistent error handling.

lib/octokit/response · high confidence

Unified Octokit module with memoized client accessors

The library now exposes a central \Octokit\ module that provides memoized accessors for \client\, \enterprise\_admin\_client\, and \manage\_ghes\_client\, automatically delegating method calls and \respond\_to?\ checks to the appropriate underlying client instance based on the current configuration options.

lib · high confidence

Fixes

The generated YARD documentation now correctly handles anchor links within the README file. A custom layout override ensures that GitHub-style hyphenated headers (e.g., \\#some-thing\) are converted to YARD-style underscored headers (e.g., \\#Some\_thing\), preventing broken internal navigation links in the generated HTML.

yard · high confidence

Test coverage

Added comprehensive test suite for Octokit core components; Added test coverage for Enterprise Admin API modules; Added test coverage for GitHub Actions, Apps, Checks, Code Scanning, and Codespaces client modules; Added test fixtures for authentication, user data, and API payloads; Added tests for GHES management client API endpoints; Initial RSpec test suite and configuration; Removed legacy test infrastructure.

Dependencies

Update dependencies and drop support for Ruby versions older than 2.7

The project has updated its dependency specifications, including major version bumps for Rubocop (to 1.69.2), RSpec (to \~\> 3.9), VCR (to \~\> 6.1), and Webmock (to \~\> 3.8), while also adding new dependencies like JWT and Faraday middleware. Additionally, the minimum required Ruby version has been raised to 2.7.0, effectively dropping support for older Ruby releases.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 68 → 66 (-2.2)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (+0.0)
  • Architecture 100 → 71 (-29.1)
  • Maturity 54 → 54 (+0.0)
  • Readiness 76 → 78 (+1.7)
  • Security 74 → 79 (+5.2)

Resolved (2)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)

New (5)

  • Inconsistent naming for deletion/removal operations. delete_label! uses an exclamation mark, while remove_label does not. Furthermore, remove_label takes a number (issue number) whereas delete_label takes a repo. This suggests different contexts (deleting a label definition vs removing a label from an issue), but the naming convention for 'deletion' is inconsistent (delete vs remove).
  • Inconsistent parameter naming for the same domain object. issue uses repo while list_issues uses repository. Similarly, update_issue uses repo but list_issues uses repository. This forces the user to guess the correct keyword argument name when switching between single-resource and collection operations.
  • Inconsistent parameter naming. milestone (singular) uses repository, while list_milestones also uses repository. However, looking at Issues, the singular issue uses repo. This creates a split convention: some singular methods use repo, others use repository. Specifically, Milestones.milestone uses repository while Issues.issue uses repo.
  • Projects may be oversized for their cohesion
  • Redundant methods with identical signatures and likely identical functionality, distinguished only by a trailing exclamation mark. In Ruby, ! often implies a destructive or raising variant, but without documentation or distinct behavior, these appear to be duplicate entry points for the same data retrieval operation.

Architecture

  • Unchanged — 0 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

octokit/octokit.rb was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6d02a4b506aaf6a6b6b1a04e065dd23c697275ce — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.