rmosolgo/graphql-ruby
61.9
Adequate · 26 September 2026
41k
lines of production code
Ruby
with C, TypeScript
5
measurements over time
What this system is
This system is the GraphQL-Ruby library, a comprehensive toolkit for building GraphQL APIs in Ruby that provides a class-based schema definition API, a high-performance C-based parser, and a flexible dataloader for efficient data fetching. It includes a web-based dashboard for monitoring schema usage, execution traces, and subscriptions, alongside a TypeScript-based JavaScript client for managing persisted queries and real-time updates. The library also offers extensive tooling for developers, including custom linters, code generators, and query analysis features to enforce complexity and depth limits.
How it got here
2015–2017 — Class-based API and execution engine rewrite
57 changes.
This period focused on a major architectural overhaul, introducing a class-based schema API, a new execution engine with multiplexing support, and a comprehensive static validation system. The project also modernized its tooling by removing legacy dependencies, adding a C parser, and launching a new documentation site and dashboard for schema inspection.
2018–2020 — Class-based schema refactoring and TypeScript client rewrite
35 changes.
This period focused on a major structural refactor of the GraphQL-Ruby schema API, migrating from the legacy DSL to a comprehensive class-based module system for types, fields, and directives. Concurrently, the JavaScript client was rewritten in TypeScript to modernize subscription handling and persisted query synchronization. The work was heavily supported by extensive integration and unit test coverage for the new pagination, validation, and execution infrastructure.
2021–2026 — Dashboard, C parser, and RuboCop integration
40 changes.
This period focused on introducing a comprehensive web dashboard for monitoring traces, subscriptions, and operations, alongside extracting the C-based parser into a standalone gem to improve performance. Significant work also included adding custom RuboCop cops to optimize schema loading and expanding test coverage for the Dataloader, visibility profiles, and the new dashboard components.
Features
Add GraphQL Operation Store listing and detail views
The GraphQL dashboard now includes user-facing views for browsing and inspecting stored operations. The index page displays a table of operations with sortable columns (Name, Aliases/Clients, Digest, Last Used At) and provides tabs to filter between active and archived items, along with bulk archive/unarchive actions. The show page presents detailed information for a specific operation, including its name, archive status, associated client aliases, last used timestamp, source code, minified body, and references.
_lib/graphql/dashboard/views/graphql/dashboard/operation\store/operations · high confidence
Add GraphQL subscription management views
The dashboard now includes views for managing GraphQL subscriptions, allowing users to browse subscription topics and inspect individual subscription details. The topics index page lists all active subscription topics with pagination and a 'Clear All' button to remove them, while the topic show page displays a list of subscriptions within a specific topic. The subscription show page provides detailed information about a single subscription, including its creation time, trigger status, context, variables, operation name, and query string.
lib/graphql/dashboard/views/graphql/dashboard/subscriptions · high confidence
Add Prometheus trace collector for GraphQL metrics
A new GraphQLCollector class has been added to the PrometheusTrace module to expose GraphQL operation durations as a Prometheus gauge metric. This collector integrates with the existing tracing infrastructure to provide observability into GraphQL performance, while maintaining backwards compatibility by aliasing the class under the legacy PrometheusTracing namespace.
_lib/graphql/tracing/prometheus\trace · high confidence
Add class-based GraphQL directive implementations
The library now includes built-in, class-based implementations for several standard and utility GraphQL directives, allowing users to leverage them directly in their schemas. This adds support for the \@deprecated\ directive to mark schema elements as unsupported, \@skip\ and \@include\ to conditionally execute fields or fragments based on boolean arguments, and \@specifiedBy\ to document scalar behavior. It also introduces \@oneOf\ to enforce that exactly one field is supplied in input objects, and \@flagged\ to hide schema members unless specific context flags are present. Additionally, example directives \@feature\ (for server-side feature flag integration) and \@transform\ (for applying string transformations like upcasing) are provided to demonstrate runtime interaction patterns.
lib/graphql/schema/directive · high confidence
Add client-side search with keyboard navigation
The guides now include a dedicated search interface powered by Algolia. Users can type queries into the search box to see up to eight results, which display the title, category, and a text preview. Navigation is supported via keyboard arrow keys to highlight and focus results, and a 'See All Results' link is provided to view the full set of matches. The search results page also links directly to specific headers within the documentation.
guides/js · high confidence
Add comprehensive benchmark suite for validation, parsing, and batch loading
The benchmark directory now includes a full suite of test assets and scripts to measure performance across key GraphQL operations. This adds specific benchmarks for validating queries with abstract fragments (including nested and overlapping fragment cases), parsing large queries and schemas, and comparing batch loading strategies using both the legacy GraphQL::Batch and the newer GraphQL::Dataloader against non-batched execution. The suite also provides infrastructure for profiling memory usage and CPU time during schema boot and query execution.
benchmark · high confidence
Add library shortcut file
A new shortcut file (graphql-c\_parser.rb) has been added to the lib directory. This file serves as a convenience entry point that requires the underlying C parser implementation, allowing users to load the library with a single require statement.
_graphql-c\parser/lib · high confidence
Add project configuration and documentation files
The repository now includes configuration files for development tooling and documentation. A \.rubocop.yml\ file is added to enforce code style, including custom cops for GraphQL-specific patterns (e.g., \DefaultNullTrue\, \DefaultRequiredTrue\) and excluding generated parser files. A \.codeclimate.yml\ file configures code quality analysis, excluding specs and generated code. A \.herb.yml\ file configures the Herb linter for HTML+ERB templates. Documentation is updated with a new \readme.md\ featuring badges, installation instructions, and links to guides, alongside a new SVG logo (\graphql-ruby.svg\). Additional files include \.gitattributes\ to mark snapshot and lock files as generated, \.gitignore\ for build artifacts, \.yardopts\ for API documentation generation, and a \CNAME\ for the website.
(repo-wide) · high confidence
Add schema index entry listing and detail views
The GraphQL Dashboard now includes dedicated views for browsing the schema operation store index. Users can view a paginated list of index entries with their usage counts and last-used timestamps, and search for specific types, fields, arguments, or enum values. Clicking an entry navigates to a detail page that shows which operations reference that entry and when it was last used, providing better visibility into schema usage patterns.
_lib/graphql/dashboard/views/graphql/dashboard/operation\_store/index\entries · high confidence
Added ESM build preparation scripts
New utility scripts have been added to the build process to prepare the ESM (ECMAScript Module) output. The \clean-esm.js\ script resets the ESM output directory, while \prepare-esm.js\ generates the ESM \package.json\ with \type: module\ and transforms CommonJS-style imports into explicit ESM-compatible paths (e.g., appending \.js\ extensions and resolving relative specifiers). This enables the client library to be consumed as native ES modules by bundlers and runtimes that support ESM.
_javascript\client/scripts · high confidence
Added JavaScript and JSON output generators for GraphQL operation syncing
New generators have been added to the \javascript\_client/src/sync/outfileGenerators\ directory to produce client-side artifacts for persisted GraphQL queries. The new \js.ts\ generator creates a JavaScript module exporting an \OperationStoreClient\ that maps local operation names to server-side persisted aliases, providing methods to retrieve operation IDs and integrate with Apollo Link and middleware APIs by replacing query strings with operation IDs. The \json.ts\ generator produces a simple JSON output containing the key-value pairs mapping operation names to their persisted aliases.
_javascript\client/src/sync/outfileGenerators · high confidence
Automatic payload type generation for mutations
Resolvers can now automatically generate return types for mutations. By defining fields within a resolver, the system creates a corresponding payload type (e.g., \MutationNamePayload\) that includes those fields, eliminating the need to manually define separate result types for mutation responses.
lib/graphql/schema/resolver · high confidence
Client management interface for Operation Store
The GraphQL Dashboard now includes a dedicated interface for managing Operation Store clients. Users can view a paginated list of clients with details such as operation counts, creation dates, and last sync times. The new views allow users to create new clients by providing a unique name and a secret authentication credential, edit existing client details, and permanently delete clients, which revokes their ability to use stored operations.
_lib/graphql/dashboard/views/graphql/dashboard/operation\store/clients · high confidence
Initial CSS styling for the guides section
This change introduces the primary stylesheet (main.scss) for the new guides section, establishing the visual design system. It defines color variables for brand, experimental, pro, and enterprise themes, along with specific styles for dark mode support (e.g., dark backgrounds, adjusted text colors). The stylesheet also implements layout rules for the header, navigation, containers, and code blocks, ensuring consistent typography and spacing across the documentation.
guides/css · high confidence
Install generator now scaffolds mutation base types and root
The GraphQL install generator has been extended to automatically create mutation support files. When running the install command, it now generates a \mutations/base\_mutation.rb\ file inheriting from \GraphQL::Schema::RelayClassicMutation\ and a \types/mutation\_type.rb\ file with a sample test field, and automatically registers the mutation root in the schema configuration.
lib/generators/graphql/install · high confidence
Introduce ActionCable subscriptions with pluggable serialization and broadcast analysis
Adds a new \ActionCableSubscriptions\ backend for GraphQL subscriptions, allowing real-time updates to be delivered via ActionCable streams. This implementation includes a \BroadcastAnalyzer\ to determine if subscription results can be shared across clients, and a \DefaultSubscriptionResolveExtension\ to handle subscription event registration and update delivery. The \Serialize\ module is updated to support time-zone-aware deserialization (handling Rails 7's \ActiveSupport::TimeWithZone\ changes), GlobalID objects, symbols, and OpenStructs, ensuring reliable round-trip serialization of subscription payloads.
lib/graphql/subscriptions · high confidence
Introduce GraphQL Dashboard with views for subscriptions, traces, limiters, and operation store
A new Rails-based dashboard engine is added to the GraphQL library, providing a web interface for monitoring and managing schema features. The dashboard includes controllers and views for detailed traces (viewing and deleting trace data), rate limiters (monitoring runtime, active operations, and mutations, and toggling soft limits), and GraphQL-Pro Subscriptions (browsing topics, viewing subscriber counts, and clearing data). It also integrates with the Operation Store, allowing users to manage API clients, view operations, and archive or unarchive operations. The dashboard enforces strict Content Security Policies and checks for the presence of specific schema features before rendering relevant sections.
lib/graphql/dashboard · high confidence
Introduce new execution engine (Execution::Next) with multiplexing and lazy resolution
The library adds a new execution engine under the \Execution::Next\ namespace, providing a modernized query processing pipeline. This engine introduces multiplex support, allowing multiple queries to be executed within a shared batching context to reduce redundant work. It features a new lazy resolution system (\Execution::Lazy\) for handling asynchronous data loading, a \Lookahead\ API for inspecting upcoming field selections to optimize data fetching, and a step-based execution model (\FieldResolveStep\, \InputValues\, \Finalize\) for more granular control over query processing. The new engine is opt-in via the \Execution::Next.use\ plugin.
lib/graphql/execution · high confidence
Introduces comprehensive argument validation DSL
This change adds a new validation framework to GraphQL arguments, allowing developers to enforce constraints directly in schema definitions. Users can now use \validates: { ... }\ to apply checks such as \format\, \inclusion\, \exclusion\, \length\, and \numericality\ to argument values. The update also introduces \required: { one\_of: \[...\] }\ to enforce mutually exclusive argument sets, \required: :nullable\ to require an argument's presence while permitting null values, and \all:\ to validate every element within an array argument. Additionally, \allow\_blank\ and \allow\_null\ options provide fine-grained control over empty or nil value handling.
lib/graphql/schema/validator · high confidence
Introduction of the GraphQL-Ruby Dashboard and major library refactoring
This change introduces a new Rails engine-based dashboard for GraphQL-Ruby, adding a landing page view at \lib/graphql/dashboard/views/graphql/dashboard/landings/show.html.erb\ that welcomes users and links to schema data. Concurrently, the core \lib/graphql.rb\ file has been significantly refactored: it now uses recursive autoloading, removes the \parslet\ and \activesupport\ dependencies in favor of standard library modules (like \delegate\, \json\, \set\), and adds a \NOT\_CONFIGURED\ constant for stricter checks. The diff also includes the lazy registration of dashboard routes within the Rails engine context to ensure they are available before routing initializers run.
lib · high confidence
Launch of the new GraphQL Ruby documentation site
The project now includes a dedicated Jekyll-based documentation site hosted at graphql-ruby.org. This new site features a landing page, a comprehensive index of guides, and a dedicated search page powered by Algolia. It also includes a development guide for contributors, an FAQ, and a list of related projects, replacing the previous documentation structure.
guides · high confidence
New ActiveRecord Dataloader sources and async execution engine
This change introduces built-in \ActiveRecordSource\ and \ActiveRecordAssociationSource\ classes to the Dataloader, allowing GraphQL-Ruby to batch-load ActiveRecord models and associations efficiently using the standard ActiveRecord Preloader. It also adds a new \AsyncDataloader\ implementation that leverages the Async gem for concurrent, fiber-based execution, replacing the previous synchronous or flat-dataloader approaches. Additionally, the \Dataloader::Source\ API is updated to use \load\ and \load\_all\ methods (replacing the deprecated \request\/\request\_all\ pattern which now returns \Request\/\RequestAll\ objects with deprecation warnings), and a \NullDataloader\ is provided for non-dataloader contexts to handle lazy resolution inline.
lib/graphql/dataloader · high confidence
New GraphQL Dashboard and runtime introspection capabilities
This release introduces a Rails-based Dashboard for inspecting schema metadata, viewing detailed execution traces, and managing operations and subscriptions. It also adds the GraphQL::Current module, which exposes fiber-local runtime information (such as the current operation name, field, and dataloader source) to facilitate integration with application logging and monitoring tools like ActiveRecord::QueryLogs.
lib/graphql · high confidence
New Jekyll plugins for API documentation, internal linking, and table of contents
Added a new \api\_doc.rb\ plugin to the guides site that introduces several Liquid tags to improve documentation usability. The \api\_doc\ tag automatically generates links to the GraphQL API reference, handling both standard Ruby identifiers and those prefixed with \GraphQL::\. A new \internal\_link\ tag allows authors to create validated links to other guide pages, ensuring the target file exists before rendering. Additionally, a \table\_of\_contents\ tag automatically generates a nested, ordered-list navigation menu from \\#\#\ headings in the guide content, and a \callout\ block supports rendering warning messages with specific styling.
_guides/\plugins · high confidence
New RangeAdd helper for Relay mutations
A new \GraphQL::Relay::RangeAdd\ helper class has been added to simplify Relay-style mutations that append items to a list. This utility automatically wraps a new item in the correct edge class and returns both the updated connection and the new edge, handling compatibility with older GraphQL-Pro versions that may not support the \range\_add\_edge\ method directly.
lib/graphql/relay · high confidence
New RuboCop cops to optimize GraphQL schema loading and reduce redundancy
The GraphQL RuboCop library now includes new rules that help optimize schema initialization and clean up redundant configuration. The \FieldTypeInBlock\ and \RootTypesInBlock\ cops encourage moving type references (for fields and root query/mutation/subscription types) into blocks to defer file loading until the types are actually needed, improving startup performance. Additionally, \DefaultNullTrue\ and \DefaultRequiredTrue\ cops detect and auto-correct explicit \null: true\ and \required: true\ arguments, which are the defaults in GraphQL-Ruby, allowing users to write cleaner, more concise schema definitions.
lib/graphql/rubocop · high confidence
New Visibility::Migration plugin for comparing Warden and Profile implementations
A new \GraphQL::Schema::Visibility::Migration\ plugin has been added to help users transition from the legacy \Warden\ authorization system to the new \Visibility::Profile\. When enabled, this plugin runs both implementations in parallel for every query and raises a \RuntimeTypesMismatchError\ if their visibility results diverge, providing a detailed diff of which types, fields, or arguments are handled differently. This allows developers to identify and fix inconsistencies in their \.visible?\ logic before fully migrating, ensuring that the new profile-based visibility behaves identically to the existing Warden setup.
lib/graphql/schema/visibility · high confidence
New application layout for the GraphQL Dashboard
The GraphQL Dashboard now uses a dedicated application layout template that provides a consistent user interface across all dashboard views. This layout includes a responsive navigation bar with links to Traces, Persisted Operations (Clients, Operations, Index), Subscriptions, and Rate Limiters (Runtime, Active Operations, and Mutations for enterprise schemas). It also integrates Bootstrap 5.3.3 for styling, supports dark mode toggling, displays flash messages, and shows the GraphQL-Ruby version and schema class in the footer.
lib/graphql/dashboard/views/layouts · high confidence
New connection and scope field extensions for pagination and authorization
Two new field extensions are introduced to handle connection pagination and object scoping. The ConnectionExtension automatically adds standard pagination arguments (first, last, before, after) to fields, strips them before passing arguments to user resolvers, and populates the connection wrapper after resolution. The ScopeExtension applies type-level scoping logic to resolved values, marking the query runtime state as authorized by scope items to prevent redundant re-authorization of scoped objects.
lib/graphql/schema/field · high confidence
New custom RuboCop rules for GraphQL development
Added five new custom RuboCop cops to enforce best practices in GraphQL Ruby code: \ContextIsPassedCop\ ensures context arguments are passed to context-aware methods; \NoEvalCop\ flags unsafe \\*\eval\ calls in favor of \\\_exec\; \NoFocusCop\ prevents focused tests from being committed; \NoneWithoutBlockCop\ suggests using \.empty?\ or adding blocks to \.any?\/\.none?\ calls; and \TraceMethodsCop\ ensures trace hooks call \super\ and include all necessary methods.
cop · high confidence
New parser caching, block string handling, and AST visitor infrastructure
The GraphQL language layer now includes a file-based parser cache (\GraphQL::Language::Cache\) that stores parsed documents to disk with HMAC-signed integrity checks, significantly speeding up repeated schema loads in applications like Rails. Block string processing has been moved to a dedicated \BlockString\ module to correctly trim whitespace and blank lines according to the GraphQL specification. Additionally, the library introduces a new \StaticVisitor\ for read-only AST traversal and a \DefinitionSlice\ utility to extract specific schema definitions and their dependencies from a document, supporting more efficient schema introspection and analysis.
lib/graphql/language · high confidence
New query analysis analyzers for field usage, complexity, and depth
This change introduces a new set of query analyzers in the \lib/graphql/analysis\ directory that allow schemas to inspect and validate incoming GraphQL queries before execution. Specifically, it adds \FieldUsage\ to track which fields, arguments, and enum values are used (including deprecated ones), \QueryComplexity\ to calculate the maximum complexity of a query with support for legacy and future calculation modes, and \QueryDepth\ to measure the nesting depth of queries. It also includes \MaxQueryComplexity\ and \MaxQueryDepth\ wrappers that enforce schema-level limits by raising \AnalysisError\ when thresholds are exceeded, and a \Visitor\ class that orchestrates the AST traversal for these analyzers.
lib/graphql/analysis · high confidence
New rake task to validate graphql-pro gem integrity
A new \graphql:pro:validate\ rake task has been added to verify the integrity of a specific graphql-pro gem version. When invoked with a version number (e.g., \rake graphql:pro:validate\[1.12.0\]\), it checks for configured credentials, fetches the gem, and compares its SHA-512 digest against published checksums from GitHub and graphql-ruby.org to ensure the download is valid and untampered.
_lib/graphql/rake\task · high confidence
New static validation error classes and schema member finder
This change introduces a comprehensive set of new error classes for GraphQL static validation rules (such as \ArgumentNamesAreUniqueError\, \FieldsAreDefinedOnTypeError\, and \FragmentsAreFiniteError\), each providing structured error codes and extensions for better error reporting. Additionally, it adds a \Schema::Finder\ class that allows users to locate schema members (types, fields, arguments, directives) using string paths (e.g., \MySchema.find("User.email")\), and introduces a \Query::Result\ class to wrap execution outcomes, providing a consistent object-oriented interface for accessing query data, context, and metadata instead of raw hashes.
graphql · high confidence
Architecture
New class-based schema traversal and visibility system
The schema definition process has been refactored to use a new class-based architecture, introducing \Schema::Addition\ to manage type registration and late-bound type resolution, and \Schema::Visibility\ (with an \AlwaysVisible\ legacy adapter) to control type and field exposure. This change replaces the previous mask-based approach with a filter-based system, enabling more granular control over which schema members are accessible and improving performance through caching and optimized traversal during schema construction.
lib/graphql/schema · high confidence
Behavioural changes
Add minimal Perfetto trace schema and generated Ruby bindings
The Perfetto tracing integration now uses a custom, abbreviated protocol buffer schema (trace.proto) that includes only the message types required for GraphQL tracing, such as TracePacket, TrackEvent, and InternedData. This change replaces any previous or external schema dependency with a minimal definition, and the corresponding Ruby classes (trace\_pb.rb) are generated from this schema to support the tracing functionality.
_lib/graphql/tracing/perfetto\trace · high confidence
Automated API documentation generation and Algolia search integration
The site build tasks now automatically generate API documentation for specific gem versions using YARD and publish them to versioned directories, while also integrating Algolia to update the search index for the documentation site. This replaces previous search tooling with Algolia, ensuring that the documentation site's search functionality is kept up-to-date during the publishing process.
_guides/\tasks · high confidence
Class-based scalar and Relay types moved to lib/graphql/types
The built-in GraphQL scalar types (ID, String, Int, Float, Boolean, BigInt, JSON, ISO8601Date, ISO8601DateTime, and ISO8601Duration) and the Relay connection/edge/page\_info types have been reorganized into the \GraphQL::Types\ namespace as class-based definitions. This change provides a consistent, class-based API for defining schema types and introduces stricter validation for scalars, such as rejecting non-finite Float values, enforcing 32-bit bounds for Int, and ensuring BigInts are parsed as base-10 integers.
lib/graphql/types · high confidence
Complete rewrite of GraphQL generators to support class-based API and new type scaffolding
The \lib/generators/graphql\ directory has been entirely replaced with a new set of generators designed for the class-based API. This change introduces dedicated generators for creating specific GraphQL types—\enum\, \input\, \interface\, \scalar\, and \union\—as well as specialized generators for Relay-style mutations (\create\, \update\, \delete\) and \GraphQL::Batch\ loaders. The \install\ generator has been updated to scaffold a modern folder structure (including \types/\, \resolvers/\, and \mutations/\ directories) and now supports optional features like GraphQL Playground, Relay conventions, and detailed query tracing. Additionally, the \DetailedTraceGenerator\ has been added to facilitate the installation of the \GraphQL::Tracing::DetailedTrace\ plugin with optional Redis persistence.
lib/generators/graphql · high confidence
Enable C-based GraphQL parser as the default
The C-based parser is now the default for GraphQL parsing in Ruby applications. This change introduces the \graphql-c\_parser\ library as the primary parsing engine, replacing the previous default implementation. Users will benefit from improved performance and stricter validation, including better handling of stack limits, standardized bad UTF-8 error reporting, and the ability to reject numbers followed immediately by names. The parser also supports schema extensions and exposes token counts for debugging purposes.
_graphql-c\parser/lib/graphql · high confidence
Extract C parser extension into a separate gem
The C-based GraphQL lexer and parser have been extracted from the main library into a standalone gem (graphql-c\_parser). This change introduces a new C extension module (graphql\_c\_parser\_ext) that exposes Ruby bindings for tokenization and parsing, including support for features like exponent-only floats, leading-zero integer handling, and schema type parsing, while removing the previous dependency on the Nodes::NONE constant.
_graphql-c\parser/ext · high confidence
GraphQL C Parser version updated to 1.1.4
The graphql-c\_parser gem version has been updated to 1.1.4, as reflected in the version.rb file. This change primarily serves to increment the version number for the C-based parser component of the GraphQL library.
_graphql-c\_parser/lib/graphql/c\parser · high confidence
GraphQL-Ruby 2.4.11: Class-based schema member refactoring and new DSL modules
This release introduces a major structural refactor of the GraphQL-Ruby schema definition API, moving from the legacy \.define\ DSL to a new class-based module system located in \lib/graphql/schema/member\. The diff adds foundational modules such as \BaseDSLMethods\ (providing \graphql\_name\, \description\, and \comment\ accessors), \BuildType\ (handling type parsing and camelization), \HasArguments\, \HasFields\, \HasInterfaces\, \HasAuthorization\, and \HasDataloader\. These modules replace previous implementation details with a cleaner inheritance chain, enabling features like lazy-loaded arguments, improved dataloader shortcuts (\dataload\, \dataload\_all\), and better support for interface implementation and field resolution. The change also includes the introduction of \GraphQLTypeNames\ constants (Boolean, ID, Int) and refactors how arguments and fields are stored and inherited, aiming to reduce runtime allocations and improve schema introspection performance.
lib/graphql/schema/member · high confidence
Introduce class-based Relay connection and edge types
The library now provides a new class-based API for defining Relay-compliant connections and edges, replacing the previous block-based DSL. Users can now inherit from \GraphQL::Types::Relay::BaseConnection\ and \GraphQL::Types::Relay::BaseEdge\ to define their types, allowing for more flexible configuration of nullability for nodes, edges, and the nodes field via class-level options like \node\_nullable\, \edges\_nullable\, and \has\_nodes\_field\. This change also introduces dedicated behavior modules (\ConnectionBehaviors\, \EdgeBehaviors\, \NodeBehaviors\) to handle pagination logic, authorization, and field definitions, providing a cleaner and more maintainable structure for Relay schema implementations.
lib/graphql/types/relay · high confidence
Introduce class-based static validation rules
The static validation engine has been rewritten using a class-based visitor pattern, replacing the previous implementation. This change introduces a comprehensive suite of validation rules (such as \ArgumentLiteralsAreCompatible\, \FieldsAreDefinedOnType\, and \FragmentsAreFinite\) that enforce GraphQL specification compliance, including stricter checks for argument uniqueness, fragment scope, and directive locations. Users will see more precise, structured error messages with extensions (e.g., \argumentLiteralsIncompatible\, \fieldConflict\) and improved performance due to optimized hot paths and caching.
_lib/graphql/static\validation/rules · high confidence
Introduce new static validation engine with timeout and error-limiting controls
The static validation layer has been replaced with a new class-based visitor architecture that validates GraphQL queries against the schema before execution. This new engine introduces a configurable \timeout\ option to abort validation if it takes too long, and a \max\_errors\ limit to stop processing once a threshold of validation errors is reached. It also provides more detailed error reporting, including specific paths to the invalid fields in the query, and integrates with the existing tracing system for observability.
_lib/graphql/static\validation · high confidence
Introspection system refactored to class-based API with new fields
The introspection schema has been rewritten using a class-based API, introducing dedicated types like \\_\Directive\, \\\Field\, \\\InputValue\, and \\\Type\ that inherit from a new \BaseObject\. This change adds support for the \includeDeprecated\ argument on fields like \fields\, \enumValues\, and \inputFields\, allowing clients to filter out deprecated items. It also introduces new introspection fields such as \specifiedByURL\ for scalars and \isOneOf\ for input objects, while deprecating legacy boolean fields like \onField\ and \onOperation\ in favor of the \locations\ list. Additionally, the system now supports dynamic introspection fields and ensures that unreachable types are filtered out from the \\\_types\ field.
lib/graphql/introspection · high confidence
JavaScript client rewritten in TypeScript with new CLI and sync options
The JavaScript client source has been rewritten in TypeScript, introducing a new CLI (\cli.ts\) for the \sync\ command that supports additional options such as \--header\, \--changeset-version\, \--dump-payload\, and outputs for Apollo Android and JSON codegen. The library now exports \sync\, \generateClient\, and subscription links (ActionCable, Pusher, Ably) from the main entry point, while generated GraphQL fragments are now placed in \\_\generated\\_\.
_javascript\client/src · high confidence
New cursor-based pagination system with bidirectional support
The pagination layer has been replaced with a new implementation that supports bidirectional pagination (using both \first\/\after\ and \last\/\before\ arguments) and introduces a schema-level connection wrapper manager. This manager automatically wraps collections from ActiveRecord, Sequel, Mongoid, and plain Arrays into connection objects, handling cursor encoding and page info. The new system includes specific connection classes for each data source to optimize queries, such as avoiding duplicate count queries for already-loaded relations and handling grouped relations correctly.
lib/graphql/pagination · high confidence
New interpreter argument handling and execution infrastructure
The interpreter now uses dedicated \ArgumentValue\ and \Arguments\ classes to manage query arguments, providing access to raw values, definitions, and metadata (such as whether defaults were used) via the new \extras: \[:argument\_details\]\ feature. An \ArgumentsCache\ is introduced to optimize argument resolution and caching, while \ExecutionErrors\ centralizes error handling and \RawValue\ allows resolvers to return raw data structures directly. The \Resolve\ module is marked deprecated in favor of the Dataloader, and the \Runtime\ class has been restructured to use a dedicated \CurrentState\ object for tracking execution context, improving how the interpreter manages field resolution and state.
lib/graphql/execution/interpreter · high confidence
New platform tracing implementations and deprecation of legacy tracers
The tracing subsystem introduces new, high-performance platform-specific trace modules (such as \ActiveSupportNotificationsTrace\, \AppOpticsTrace\, \DataDogTrace\, \NewRelicTrace\, \PerfettoTrace\, and \DetailedTrace\) that replace the older \PlatformTracing\ classes. The legacy tracers (e.g., \AppOpticsTracing\, \DataDogTracing\) are now deprecated and emit warnings, directing users to migrate to the new modules. Additionally, a \CallLegacyTracers\ module is provided to maintain compatibility with older custom tracer implementations during the transition.
lib/graphql/tracing · high confidence
New query execution context, validation pipeline, and variable handling
The query execution engine now uses a dedicated \GraphQL::Query::Context\ class to manage field resolution state, introducing scoped context storage that allows values to be set and inherited along specific query paths. A new \ValidationPipeline\ orchestrates the validation sequence (AST, variables, and analyzers) and enforces \validate\_max\_errors\ limits. Variable processing has been refactored into a \Variables\ class that separates validation from coercion, producing detailed \VariableValidationError\ objects with specific problem paths and extension data for better error reporting.
lib/graphql/query · high confidence
Redesigned documentation site with dark mode and search
The guides documentation layout has been updated to include a new header with navigation links, a search input powered by Algolia, and a toggle for dark mode that persists user preference and swaps the site logo. Guide pages now feature a breadcrumb navigation with dropdowns for sections and pages, a table of contents, and clickable headers for easy linking. Additionally, specific banners are displayed for experimental, Pro, and Enterprise features, and an edit link is provided for community contributions.
_guides/\layouts · high confidence
Refactor schema resolution logic into dedicated ResolveMap classes
The internal implementation of \Schema.build\_from\_definition\ has been refactored to use new \ResolveMap\ and \DefaultResolve\ classes. This change restructures how user-provided resolution hashes are processed at runtime, introducing optimized path resolution for scalar coercion and field execution. For users, this is an internal architectural improvement that maintains existing behavior while improving the maintainability and performance of schema construction from SDL strings.
_lib/graphql/schema/build\_from\definition · medium confidence
Refactored result handling to ensure correct key ordering in GraphQL responses
The runtime's result object implementation has been refactored to guarantee that keys in GraphQL response objects appear in the order defined by the query selection set. This change introduces dedicated result classes (GraphQLResultHash, GraphQLResultArray) that track and enforce key order during result construction, addressing previous issues where result order could be incorrect or inconsistent. Users will now receive response objects with keys strictly ordered according to the GraphQL query structure, improving predictability and compatibility with systems that depend on field ordering.
lib/graphql/execution/interpreter/runtime · high confidence
Rewrite GraphQL sync client in TypeScript with new CLI options and Apollo/Relay support
The JavaScript sync client in \javascript\_client/src/sync\ has been rewritten in TypeScript, introducing several new capabilities for managing GraphQL persisted queries. Users can now generate output files without sending data to a server by omitting the URL, and can dump the HTTP payload to stdout or a file using the new \--dump-payload\ option. The sync process now automatically strips \@client\ fields from queries before syncing to ensure document validity, and supports reading operation artifacts from Apollo Android (\--apollo-android-operation-output\), Apollo Codegen JSON (\--apollo-codegen-json-output\), and Relay compiler outputs. Additionally, custom HTTP headers can be added via \--header\, and a \changeset-version\ can be passed to populate server-side context.
_javascript\client/src/sync · high confidence
Rewritten subscription clients in TypeScript with new Ably and Pusher support
The subscription layer in \javascript\_client/src/subscriptions\ has been rewritten in TypeScript, introducing dedicated handlers and fetchers for Ably, Pusher, and ActionCable alongside existing Apollo and Urql integrations. This update adds native support for Ably subscriptions (including encryption via \X-Subscription-Key\ and presence channels) and Pusher subscriptions (including compressed result handling), while also modernizing the ActionCable implementation to support persisted queries and custom channel names. The rewrite improves reliability by fixing race conditions in subscription disposal, ensuring proper unsubscription logic across all transports, and using \crypto.randomUUID\ for channel IDs with a fallback to \getRandomValues\ for non-secure contexts.
_javascript\client/src/subscriptions · high confidence
Structured GraphQL backtrace and error reporting
Errors raised during GraphQL execution are now wrapped in a TracedError that includes a structured, human-readable table of the execution context. This table displays the location, field name, object, arguments, and result for each step in the query path, making it significantly easier to debug complex queries. The error message also includes a preview of the original Ruby backtrace and instructions on how to access the full cause chain.
lib/graphql/backtrace · high confidence
Thread-safe lazy method resolution map
The lazy execution layer now uses a thread-safe map to cache the mapping between lazy value classes and their resolution methods. This implementation supports concurrent-ruby's Concurrent::Map for improved performance and safety, while providing a mutex-backed fallback (ConcurrentishMap) for environments where the library is not available, ensuring correct behavior during concurrent schema introspection and execution.
lib/graphql/execution/lazy · high confidence
Updated generator templates for class-based API and Relay integration
The generator templates in lib/generators/graphql/templates have been rewritten to support the library's class-based API. Base types (Object, Input, Enum, Scalar, Union, Interface, Argument, Field) now inherit from specific GraphQL::Schema base classes and configure their respective field/argument classes. Relay support is integrated via new BaseConnection and BaseEdge templates that include GraphQL::Types::Relay behaviors, and a NodeType template. The schema template now defaults to using GraphQL::Dataloader (with an option for GraphQL::Batch), includes a type\_error hook, and sets validation limits. New mutation templates (Create, Update, Delete) are provided alongside a generic mutation template, and the controller template now handles variables more robustly and provides detailed error logging in development.
lib/generators/graphql/templates · high confidence
Test coverage
Add Star Wars test schema with class-based types and connection support; Added ActionCable subscription helper for dummy app testing; Added ActionCable subscription test fixtures; Added ActionCable test page for subscription and fingerprint scenarios; Added GraphQL schema definition for Magic Cards tests; Added GraphQL test fixtures and mock infrastructure; Added Jest snapshots for sync client generation tests; Added Mongoid integration test suite for Star Trek schema; Added Rails environment configuration files for the dummy test application; Added application layout template for dummy app tests; Added autoload verification script to the dummy application; Added base test class for Rails generator integration tests; Added comprehensive test coverage for GraphQL core components; Added comprehensive test coverage for GraphQL language parsing components; Added comprehensive test coverage for GraphQL query execution internals; Added comprehensive test suite for GraphQL schema components; Added comprehensive test suite for the new GraphQL execution engine; Added dummy Rails application scaffolding for testing; Added end-to-end test for GraphQL ActionCable channel; Added integration tests for ActiveSupport Notifications tracing; Added integration tests for GraphQL Rails generators; Added integration tests for GraphQL and ActiveRecord query logging; Added integration tests for GraphQL query variable handling; Added integration tests for Mongoid GraphQL Relay connections; Added integration tests for Rails GraphQL features; Added integration tests for Relay connection implementations; Added integration tests for the GraphQL Dashboard controllers; Added integration tests for the Limiter dashboard controller; Added integration tests for the Operation Store dashboard controllers; Added regression tests for warning-free loading and updated test infrastructure; Added system test infrastructure and test helpers; Added system tests for ActionCable subscription management; Added test coverage for Dataloader sources and execution modes; Added test coverage for GraphQL introspection behavior; Added test coverage for GraphQL pagination connections; Added test coverage for GraphQL query analysis features; Added test coverage for GraphQL scalar types; Added test coverage for GraphQL schema validators; Added test coverage for GraphQL static validation rules; Added test coverage for GraphQL tracing integrations; Added test coverage for Relay connection and edge nullability configurations; Added test coverage for dummy app initializers; Added test coverage for schema directive features; Added test coverage for schema member utilities; Added test dummy application configuration; Added test fixtures for GraphQL RuboCop cops; Added test fixtures for GraphQL parser validation; Added test fixtures for nested autoloaded modules; Added test fixtures for the class-based dummy schema; Added test fixtures for unicode escape handling in block strings; Added test support infrastructure and removed legacy test fixtures; Added tests for AsyncDataloader fiber-level database connection isolation; Added tests for DetailedTrace backend implementations; Added tests for GraphQL RuboCop cops; Added tests for GraphQL Schema Visibility Profile behavior; Added tests for GraphQL TypeKind leaf status; Added tests for GraphQL field connection extension behavior; Added tests for GraphQL subscription dashboard views; Added tests for GraphQL testing helpers; Added tests for ISO8601Duration scalar type; Added tests for LazyMethodMap concurrency and duplication; Added tests for scoped context in GraphQL query execution; Added tests for the JavaScript client sync CLI and ESM exports; Added tests for the JavaScript sync client utilities; Added tests for the detailed traces controller; Added unit tests for GraphQL::Execution::Interpreter::Arguments; Added unit tests for JavaScript subscription clients; New testing helpers for field resolution and visibility assertions; Static validation test suite for the new validator implementation.
Dependencies
Expanded CI compatibility with Rails 7.2, 8.0, 8.1, and Mongoid 8/9
The gemfile suite has been updated to support testing against newer versions of Rails (7.2, 8.0, and 8.1) and Mongoid (8 and 9). New appraisal gemfiles define dependencies for these versions, including specific constraints like pinning JSON to less than version 3 for Rails 8.0 compatibility. The suite also includes configurations for Rails master (main branch) and PostgreSQL backends, ensuring broader framework compatibility for users upgrading their environments.
gemfiles · high confidence
Introduce C parser gem and modernize JavaScript client and Ruby dependencies
This update introduces the \graphql-c\_parser\ gem, a new C-extension-based parser for GraphQL requiring Ruby 3.0+, and adds it as a dependency for the main \graphql\ gem. The JavaScript client (\graphql-ruby-client\) is upgraded to version 1.16.0, now supporting ESM builds, TypeScript 6, and Apollo Client 4, while moving \graphql\ and \@apollo/client\ to peer dependencies. The Ruby project's dependency structure is significantly modernized: \activesupport\ and \parslet\ are removed in favor of standard library gems (\base64\, \fiber-storage\, \logger\), development tooling is updated to include \rubocop\, \simplecov\, and \stackprof\, and the \Gemfile.lock\ is removed to streamline dependency management.
(dependencies) · high confidence
Updated dashboard to Bootstrap 5.3.3
The static stylesheets for the GraphQL dashboard have been updated to use Bootstrap version 5.3.3. This upgrade brings the latest styling, component behavior, and CSS variables from the Bootstrap framework to the dashboard interface.
lib/graphql/dashboard/statics · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 57 → 62 (+4.8)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 84 → 88 (+4.1)
- Architecture 94 → 100 (+6.1)
- Maturity 88 → 83 (-5.3)
- Readiness 32 → 68 (+35.6)
- Security 68 → 69 (+0.5)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 48 (new)
Resolved (23)
- Change coupling: ActionCableSubscriber.ts ↔ addGraphQLSubscriptions.ts (javascript_client/src/subscriptions/ActionCableSubscriber.ts)
- Change coupling: ActionCableSubscriber.ts ↔ createActionCableHandler.ts (javascript_client/src/subscriptions/ActionCableSubscriber.ts)
- Change coupling: SubscriptionExchange.ts ↔ createActionCableHandler.ts (javascript_client/src/subscriptions/SubscriptionExchange.ts)
- Change coupling: addGraphQLSubscriptions.ts ↔ createActionCableHandler.ts (javascript_client/src/subscriptions/addGraphQLSubscriptions.ts)
- Change coupling: cli.ts ↔ sendPayload.ts (javascript_client/src/cli.ts)
- Change coupling: index.ts ↔ prepareIsolatedFiles.ts (javascript_client/src/sync/index.ts)
- Change coupling: index.ts ↔ prepareProject.ts (javascript_client/src/sync/index.ts)
- Change coupling: index.ts ↔ sendPayload.ts (javascript_client/src/sync/index.ts)
- Change coupling: jest.config.js ↔ index.ts (javascript_client/jest.config.js)
- Change coupling: prepareIsolatedFiles.ts ↔ prepareProject.ts (javascript_client/src/sync/prepareIsolatedFiles.ts)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (11 lines × 3) (lib/graphql/schema/addition.rb)
- Duplicated block (18 lines × 2) (lib/graphql/language/parser.rb)
- High CVE: [GHSA redacted] (javascript_client/package-lock.json)
- High CVE: [GHSA redacted] (javascript_client/package-lock.json)
- High: security finding (details withheld)
- Low CVE: [GHSA redacted] (javascript_client/package-lock.json)
- Medium CVE: [GHSA redacted] (javascript_client/package-lock.json)
- Medium: security finding (details withheld)
- …and 3 more
New (294)
- Addition.add_type (cognitive 63) (lib/graphql/schema/addition.rb)
- Addition.add_type (cyclomatic 33) (lib/graphql/schema/addition.rb)
- Addition.update_type_owner (cognitive 33) (lib/graphql/schema/addition.rb)
- Addition.update_type_owner (cyclomatic 20) (lib/graphql/schema/addition.rb)
- Argument.load_and_authorize_value (cognitive 17) (lib/graphql/schema/argument.rb)
- ArgumentLiteralsAreCompatible.on_argument (cognitive 29) (lib/graphql/static_validation/rules/argument_literals_are_compatible.rb)
- ArgumentObjectLoader.authorize_application_object (cognitive 28) (lib/graphql/schema/member/has_arguments.rb)
- ArrayConnection.load_nodes (cognitive 20) (lib/graphql/pagination/array_connection.rb)
- ArrayConnection.load_nodes (cyclomatic 16) (lib/graphql/pagination/array_connection.rb)
- AsyncDataloader.run_queue (cognitive 19) (lib/graphql/dataloader/async_dataloader.rb)
- BlockString.trim_whitespace (cognitive 21) (lib/graphql/language/block_string.rb)
- BlockString.trim_whitespace (cyclomatic 20) (lib/graphql/language/block_string.rb)
- BuildType.parse_type (cognitive 26) (lib/graphql/schema/member/build_type.rb)
- BuildType.parse_type (cyclomatic 26) (lib/graphql/schema/member/build_type.rb)
- Builder.build (cognitive 61) (lib/graphql/schema/build_from_definition.rb)
- Builder.build (cyclomatic 44) (lib/graphql/schema/build_from_definition.rb)
- Change coupling: array_connection.rb ↔ relation_connection.rb (lib/graphql/pagination/array_connection.rb)
- Dataloader.run_pending_steps (cognitive 21) (lib/graphql/dataloader.rb)
- DefaultSubscriptionResolveExtension.resolve (cognitive 17) (lib/graphql/subscriptions/default_subscription_resolve_extension.rb)
- DefinitionDependencies.resolve_dependencies (cognitive 19) (lib/graphql/static_validation/definition_dependencies.rb)
- …and 274 more
Changes since last survey
- 134 commits — 113 feature/other, 21 fixes
By area
- (repo) — 58 commits
- lib/graphql — 40 commits
- .github/workflows — 7 commits
- spec/graphql — 6 commits
- (root) — 5 commits
- javascript_client/package-lock.json — 4 commits
- javascript_client/src — 4 commits
- graphql-c_parser/ext — 3 commits
- gemfiles/mongoid_8.gemfile — 1 commit
- guides/dataloader — 1 commit
- javascript_client/CHANGELOG.md — 1 commit
- javascript_client/package.json — 1 commit
- spec/dummy — 1 commit
- spec/integration — 1 commit
- spec/support — 1 commit
Notable commits
- fix: Execution::Next: fix NoMethodError when a non-null root mutation field adds an error
- fix: Fix C parser compiler warnings
- fix: Fix lexer columns after newlines
- fix: Fix lexer positions for multibyte input
- fix: Merge branch 'master' into fix-async-dataloader-nested-run-isolated
- fix: Merge pull request #5687 from ydah/fix-trace-mode-test-state-leak
- fix: Merge pull request #5688 from ydah/fix-dashboard-schema-selection
- fix: Merge pull request #5692 from ydah/fix/lexer-byte-offset-line-number
- fix: Merge pull request #5697 from ydah/fix/lexer-column-after-newline
- fix: Merge pull request #5698 from drhops/fix-execution-next-mutation-root-null-propagation
- fix: Merge pull request #5702 from drhops/fix-async-dataloader-closed-queue-race
- fix: Merge pull request #5703 from drhops/fix-async-dataloader-nested-run-isolated
- fix: Merge pull request #5708 from drhops/fix-pagination-relation-connection-fiber-safety
- fix: Merge pull request #5719 from ydah/fix-c-parser-large-float-literals
- fix: Merge pull request #5721 from ydah/fix-c-parser-function-prototypes
- fix: Merge pull request #5728 from ydah/fix-execution-next-multiplex-result-alignment
- fix: Merge pull request #5736 from ydah/fix-action-cable-system-test-isolation
- fix: Merge pull request #5739 from ydah/fix-next-runtime-directive-defaults
- fix: Merge pull request #5740 from ydah/fix-next-scalar-partials
- fix: Merge pull request #5742 from ydah/fix-query-result-default-execution
- …and 114 more
Architecture
- Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed
Added bounded contexts (1)
- graphql
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
rmosolgo/graphql-ruby was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 454b4136c1417ec17c122ed99d8acbe458857712 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.