pabloh/pathway
68.3
Adequate · 22 September 2026
775
lines of production code
Ruby
primary language
7
measurements over time
What this system is
Pathway is a Ruby library that provides a plugin-based architecture for building and managing operations with robust error handling. It introduces a Result object for state management and supports extensibility through a plugin system that adds features like validation, authorization, and transactional steps. The system also includes comprehensive RSpec matchers for testing operations and form schemas.
Features
Add RSpec matchers for validating form schemas and operations
Introduces new RSpec matchers for testing form schemas and operations. The \require\_fields\ and \accept\_optional\_fields\ matchers allow assertions about field presence, optionality, and null-value handling, including chain methods like \allowing\_null\_values\ and \not\_allowing\_null\_values\. Additionally, \succeed\_on\ and \fail\_on\ matchers are added to verify the success or failure of operations, supporting chained assertions on return values, error types, messages, and details.
lib/pathway/rspec · high confidence
Introduce plugins architecture with new capabilities
The library now features a plugins architecture, introducing several new plugins: \auto\_deconstruct\_state\ for automatic state deconstruction, \dry\_validation\ for integrating Dry::Validation 1.0+ with automatic wire support, \responder\ for handling success/failure blocks on operation calls, \sequel\_models\ for fetching and managing Sequel models with configurable search fields and error messages, and \simple\_auth\ for adding authorization blocks. These plugins add new methods and behaviors to operations, such as \transaction\ and \after\_commit\ steps in \sequel\_models\, and \call\ with success/failure handling in \responder\.
lib/pathway/plugins · high confidence
Behavioural changes
Introduces Result and Error objects for improved error handling
The library now provides a Result object with Success and Failure states, allowing for more robust error handling and state management. This change introduces a new way to handle errors and success cases, moving away from previous error handling mechanisms. The Result object includes methods for chaining operations and handling both success and failure scenarios, enhancing the overall reliability of the library.
lib/pathway · high confidence
Introduces a plugin-based architecture and new DSL methods for operations
The library now supports a plugin system where operations can extend functionality via the \plugin\ method, which dynamically loads and applies modules for class, instance, and DSL behavior. This enables new capabilities such as conditional execution with \if\_true\/\if\_false\ (aliased as \guard\), state modification via \set\ with a \:to\ option, and transactional steps via \around\. The \State\ object now supports destructuring and pattern matching, and includes a \use\ method for accessing state values. Additionally, the \Error\ class has been refactored to support default messages and pattern matching, and the \Inflector\ is now backed by \dry-inflector\.
lib · high confidence
Updated Ruby bin scripts and console configuration
The \bin\ directory was updated to include newly generated Binstubs for various Ruby tools (such as \byebug\, \coderay\, \erb\, \htmldiff\, \irb\, \ldiff\, \pry\, \racc\, \rbs\, \rdbg\, \rdoc\, \ri\, \rspec\, \rubocop\, \ruby-lsp\, \ruby-parse\, \ruby-rewrite\, \sequel\, \yard\, \yri\, and \rake\). Additionally, the \bin/console\ script was modified to use \Pry\ instead of \IRB\ for the interactive console.
bin · high confidence
Test coverage
Added RSpec matchers for operation results; Added comprehensive test coverage for all plugins; Added comprehensive test coverage for core Pathway components.
Dependencies
Update Ruby and dependency requirements
The gem now requires Ruby 3.3.0 or higher and replaces the 'inflecto' dependency with 'dry-inflector' (\>= 0.1.0). Development dependencies have been updated to include 'dry-validation' \>= 1.0, 'bundler' \>= 2.4.10, 'rspec' \~\> 3.11, and various new tools like 'rubocop' and 'pry-doc'.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 64 → 68 (+3.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 57 → 62 (+4.9)
- Readiness 58 → 65 (+7.1)
- Security 100 → 96 (-4.0)
Resolved (6)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further orphaned files (smaller)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
New (13)
- Documentation: no installation or build instructions (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No dependency advisory monitoring
- Redundant authorization methods. Similar to the validation plugin, having authorize and authorize_with creates ambiguity. authorize_with suggests passing objects directly, while authorize takes a state and a 'using' argument. The intent of the 'using' argument vs the 'objs' argument is not immediately distinct in signature.
- Redundant validation methods with unclear distinction. validate takes a state and a 'with' argument, while validate_with takes an input. It is unclear if these are for different stages of execution or if one is a convenience wrapper for the other, leading to potential confusion on which to use.
- Workflow token permissions not restricted
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
pabloh/pathway was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d4c4524136ade13000bde233c3f28ee0ee9b608f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.