Skip to content
CAI
Software that uses CAICheck a score

varvet/pundit

64.2

Adequate · 26 September 2026

1k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Pundit is a Ruby gem that provides a structured authorization framework for Rails applications, enabling developers to define and enforce access policies for controllers and models. It offers a context-based mechanism for managing user permissions and policy caching, along with generators to scaffold policy classes and tests. The system supports integration with RSpec for testing authorization logic and includes utilities for managing policy scopes and permitted attributes.

How it got here

2012 — Context-based authorization refactoring

6 changes.

This period focused on restructuring Pundit's internal authorization logic around a new request-scoped Context class to manage user state and policy caching. The update introduced generators for scaffolding policies, added comprehensive test coverage, and established a new linting infrastructure using RuboCop and StandardRB.

2014–2025 — test infrastructure and development tooling

6 changes.

This period focused on expanding test coverage for Pundit's authorization policies, context classes, and view helpers by introducing comprehensive mock models, policies, and support utilities. It also established development convenience scripts to streamline local environment setup and interactive experimentation.

Features

Added development convenience scripts

New executable scripts have been added to the bin directory to streamline the local development workflow. The bin/console script provides an interactive Ruby IRB environment with Bundler and Pundit pre-loaded, facilitating easier experimentation with the gem's code. The bin/setup script automates the initial environment configuration by running bundle install, ensuring dependencies are ready for development.

bin · high confidence

New generators for application and model policies with test scaffolding

The library now includes Rails generators to scaffold Pundit policies. Running \rails generate pundit:install\ creates a base \ApplicationPolicy\ class with default deny-all permissions and a scope structure. Running \rails generate pundit:policy \<name\>\ generates a model-specific policy inheriting from \ApplicationPolicy\ and automatically creates corresponding test files for either RSpec or Test::Unit, depending on the project's test framework.

lib/generators · high confidence

Behavioural changes

Deprecate direct inclusion of Pundit module in favor of Pundit::Authorization

Including the \Pundit\ module directly in controllers or helpers is now deprecated and will emit a warning directing users to include \Pundit::Authorization\ instead. The \Pundit\ module now acts as a shim that delegates to \Pundit::Authorization\, while also exposing class-level methods (\authorize\, \policy\, \policy\_scope\, etc.) that create a \Pundit::Context\ to handle authorization logic. This change separates the core authorization logic into its own module and introduces a context-based approach for managing user and policy cache state.

lib · high confidence

Pundit authorization logic restructured around a request-scoped Context and cache stores

Pundit's internal authorization mechanism has been refactored to use a new \Pundit::Context\ class that encapsulates the current user and a policy cache for the duration of a request. Controller helpers in \Pundit::Authorization\ now delegate to this context, and the previous \policies\ cache method is deprecated in favor of \pundit\_policies\. A new \CacheStore\ interface is introduced with \LegacyStore\ (caching by record only) and \NullStore\ (no caching) implementations, allowing for more flexible policy lookup caching. Additionally, a \pundit\_reset!\ method is added to clear cached authorization data when the user context changes, and RSpec integration is updated to support the \:focus\ metadata for filtering tests.

lib/pundit · high confidence

Update to Pundit 2.5.2 and introduce RuboCop/Standard linting

This release updates the gem to version 2.5.2 and introduces a new linting infrastructure using RuboCop and StandardRB. The configuration files \.rubocop\_ignore\_git.yml\ and \.standard.yml\ are added to manage code style, with the latter extending the RuboCop config and targeting Ruby 3.2. The \Rakefile\ is updated to include tasks for running RSpec, YARD documentation, and RuboCop checks. The changelog notes fixes for RSpec 4 compatibility, a deprecation of \Pundit::Authorization\#policies\ in favor of \\#pundit\_policies\, and improved error handling for the \permissions\ matcher.

(repo-wide) · high confidence

Test coverage

Added comprehensive test suite for Pundit authorization and policy resolution; Added test coverage for PostPolicy permissions; Added test coverage for Pundit::Context and view-level policy\_scope; Added test support models for Pundit policy testing; Added test support policies for Pundit coverage; Added test support utilities for controller, cache, and instance tracking.

Dependencies

Updated gemspec metadata and added development dependencies

The Pundit gemspec has been updated to include comprehensive metadata such as license, homepage, and issue tracker URIs, and authors have been expanded to include Varvet AB. Additionally, the Gemfile now explicitly lists development and testing dependencies including RSpec, SimpleCov, Standard, and Logger (to address JRuby 9.3 compatibility), while the gemspec adds a runtime dependency on ActiveSupport.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 47 → 64 (+16.8)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 59 → 58 (-1.2)
  • Readiness 25 → 57 (+31.7)
  • Security 74 → 100 (+26.3)

Resolved (15)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Test reliability not included
  • The installation note states 'Please note that the README on GitHub is accurate with the latest code on GitHub', but there is no guidance on how to update the documentation when new releases appear. (README.md)

New (16)

  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent parameter naming and structure for the same core operation. The module-level Pundit.authorize takes explicit user and record arguments, while the context-level Context.authorize takes a single possibly_namespaced_record (implying user is derived from context) and uses different argument ordering/naming for optional params.
  • Inconsistent parameter structure for policy retrieval. Pundit.policy accepts a flexible args, kwargs, block signature, while Context.policy takes a single record. This creates confusion about how to pass additional options or blocks when using the context.
  • Inconsistent parameter structure for policy scoping. Pundit.policy_scope takes user and flexible args/kwargs, while Context.policy_scope takes a single scope object. This inconsistency extends to the bang versions as well.
  • Inconsistent parameter structure for the bang version of policy retrieval. Same issue as policy vs policy!.
  • Inconsistent parameter structure for the bang version of policy scoping. Same issue as policy_scope vs policy_scope!.
  • No dependency advisory monitoring
  • Off-boarding risk: anonymized user #1

Changes since last survey

  • 8 commits — 8 feature/other, 0 fixes

By area

  • (root) — 4 commits
  • (repo) — 3 commits
  • spec/pundit — 1 commit

Notable commits

  • change: Add specs for Pundit::Context
  • change: Merge pull request #880 from varvet/kbs/update-readme-sponsorship
  • change: Merge pull request #882 from varvet/kbs/tagged-permits
  • change: Merge pull request #884 from varvet/kbs/janitorial
  • change: Rename Authorization#policies to #pundit_policies
  • change: Require blank? alongside inflections
  • change: Test and document hash filters in permitted attributes
  • change: Update Varvet sponsorship to be clearer

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

varvet/pundit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a05c6f19e1aae713597db82562bb4eb752ac4bf5 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.