sporkmonger/addressable
69.0
Adequate · 19 September 2026
8.2k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
Addressable is a Ruby library for parsing, manipulating, and normalizing URIs and internationalized domain names. It provides robust support for RFC 6570 URI Templates and handles IDNA conversions via both native C libraries and a pure-Ruby fallback. The system includes comprehensive security measures against ReDoS vulnerabilities and ensures compatibility with modern Ruby versions through frozen string literal support.
Features
Add top-level require for addressable library
Users can now call \require 'addressable'\ to load the library, which automatically requires \addressable/uri\ and \addressable/template\. The file also includes the \frozen\_string\_literal\ pragma for performance and safety.
lib · high confidence
Addressable 2.9.0: New IDNA fallback, URI Templates, and frozen string support
This release introduces a pure-Ruby IDNA implementation as a fallback when the native libidn gem is unavailable, ensuring consistent internationalized domain name handling across environments. It adds full support for RFC 6570 URI Templates, allowing users to expand and match templates against URIs via the new Addressable::Template class. The library also updates its core URI parsing and normalization logic to fully support Ruby's frozen string literals, preventing mutation errors in modern Ruby versions, and bumps the version to 2.9.0.
lib/addressable · high confidence
Behavioural changes
Addressable 2.9.0 release and repository restructuring
This release introduces Addressable 2.9.0, which fixes a ReDoS vulnerability in Addressable::Template\#match that remained after the incomplete remediation in version 2.8.10. The repository has been restructured to improve developer experience and security: the license has been updated to Apache 2.0, documentation is now maintained in Markdown (README.md, CHANGELOG.md), and the gemspec generation has been rewritten. Development tooling has been modernized by switching from RCov to SimpleCov for code coverage, adding a .simplecov configuration, and updating the .gitignore to exclude build artifacts like .DS\_Store, vendor/, and Gemfile.lock. The Rakefile has been cleaned up to explicitly list packaged files and remove unnecessary LOAD\_PATH management.
(repo-wide) · high confidence
IDNA implementation refactored with native libidn support and deprecated normalization method
The IDNA module now includes a new native implementation (\lib/addressable/idna/native.rb\) that delegates to the \libidn\ C library for ASCII conversion, utilizing the \ALLOW\_UNASSIGNED\ flag. The pure Ruby implementation (\lib/addressable/idna/pure.rb\) has been updated to use Ruby's built-in \unicode\_normalize(:nfkc)\ instead of legacy custom logic, and the \unicode\_normalize\_kc\ method is now explicitly deprecated in favor of the standard library method.
lib/addressable/idna · high confidence
Rake tasks rewritten for gem packaging, release, and documentation
The build and release workflow has been restructured into a new set of Rake tasks. The \tasks/gem.rake\ file now handles gem specification generation (including metadata like changelog URIs and license info), packaging, and installation, while \tasks/git.rake\ manages the release process by validating version consistency and creating annotated Git tags. Documentation generation has switched to YARD with Markdown support via \tasks/yard.rake\, and test coverage reporting now uses SimpleCov with a browse task via \tasks/rspec.rake\. Additionally, new tasks for memory profiling (\tasks/profile.rake\) and code metrics (\tasks/metrics.rake\) have been added to aid in performance analysis.
tasks · high confidence
Test coverage
Added benchmark scripts for URI normalization performance; Expanded test coverage for IDNA, URI templates, and security edge cases; Standardized test configuration and coverage reporting.
Dependencies
Addressable 2.9.0 release with updated dependencies and Ruby version requirements
This release updates the gemspec to version 2.9.0, raising the minimum required Ruby version to 2.2 and updating the runtime dependency on public\_suffix to allow versions \>= 2.0.2 and \< 8.0. The Gemfile introduces explicit test dependencies (rspec \~\> 3.8, rspec-its \~\> 1.3), coverage tools (coveralls, simplecov), and development dependencies (launchy, yard, memory\_profiler, rake \>= 12.3.3), while conditionally including idn-ruby for MRI platforms unless the IDNA\_MODE environment variable is set to 'pure'.
(dependencies) · high confidence
Support for public\_suffix v7
The gemfiles now include a dedicated configuration for public\_suffix version 7, allowing the library to be used with this newer major version alongside existing support for versions 2 through 6.
gemfiles · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 69.
Lenses
- Code Health 86
- Architecture 100
- Maturity 55
- Readiness 78
- Security 81
Changes since last survey
- 300 commits — 265 feature/other, 35 fixes
By area
- (root) — 78 commits
- .github/workflows — 70 commits
- (repo) — 68 commits
- lib/addressable — 62 commits
- spec/addressable — 8 commits
- tasks/gem.rake — 5 commits
- tasks/profile.rake — 3 commits
- .github/dependabot.yml — 2 commits
- spec/spec_helper.rb — 2 commits
- data/unicode.data — 1 commit
- tasks/rspec.rake — 1 commit
Notable commits
- fix: CI: Ractor fix for Ruby 4.0
- fix: CI: fix profile:template_match_memory task for Ruby >2.7
- fix: Fix JRuby CI failures
- fix: Fix RubyGems deprecation warning
- fix: Fix YAML serialization (#508)
- fix: Fix a ReDoS vulnerability in URI template matching
- fix: Fix broken test workflow
- fix: Fix encoding ipv6 literals
- fix: Fix failing Travis builds
- fix: Fix gemspec generation (#517)
- fix: Fix heading levels in README and Changelog
- fix: Fix link in CHANGELOG, add missing space in RELEASING (#563)
- fix: Fix links for 2.8.9 in CHANGELOG (#573)
- fix: Fix template expand level 2 hash support for non-string objects (#499)
- fix: Fix thread safety issue with encoding tables (#515)
- fix: Fix truffleruby CI failure
- fix: Fix warnings when running specs
- fix: Fixed Addressable::URI#inspect to use self.class. (#544)
- fix: Merge branch 'master' into rm-fix-rspec-expecation
- fix: Merge pull request #302 from dentarg/request_uri-fix
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sporkmonger/addressable was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d298c9f551fa9748d16dbfb6273b70f60b3d61bc — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.