activerecord-hackery/ransack
68.2
Adequate · 26 September 2026
3.7k
lines of production code
Ruby
primary language
4
measurements over time
What this system is
Ransack is a Ruby gem that provides dynamic search and sorting capabilities for Active Record models. It enables developers to construct complex queries through form helpers and a flexible node-based architecture, supporting features like attribute aliases, ransackers, and multi-database compatibility. The system prioritizes security by enforcing strict validation on search parameters to prevent denial-of-service attacks, while maintaining ORM agnosticism through lazy-loaded adapters.
Features
Add Turbo integration and refine form builder options
The form helpers now support Hotwire/Turbo via a new \turbo\_search\_form\_for\ helper that submits via Turbo streams, and the \FormBuilder\ can be dynamically swapped via the \RANSACK\_FORM\_BUILDER\ environment variable (e.g., to use SimpleForm). Additionally, \attribute\_select\ and \predicate\_select\ now accept \:default\ and \:only\ options to customize initial selections and filter available predicates, while \sort\_select\ is split into separate \attribute\_select\ and \sort\_direction\_select\ calls for better flexibility.
lib/ransack/helpers · high confidence
Removals
Removal of legacy ActiveRecord adapter files
The \lib/ransack/adapters/active\_record/base.rb\ and \lib/ransack/adapters/active\_record/context.rb\ files have been deleted. This removes the legacy implementation of the \search\ method aliasing and the custom \Context\ class that handled query evaluation, association resolution, and join dependency building for ActiveRecord. Users relying on these specific internal adapter components will need to ensure their codebase uses the current adapter structure.
_lib/ransack/adapters/active\record · high confidence
Behavioural changes
Active Record integration refactored into Ransack::ActiveRecord with stricter search validation
The Active Record adapter has been moved from Ransack::Adapters::ActiveRecord to Ransack::ActiveRecord, with the old namespace retained only for backward compatibility with a deprecation warning. This change introduces stricter validation for search parameters: unknown conditions now raise Ransack::InvalidSearchError by default (unless \ignore\_unknown\_conditions\ is explicitly enabled), and search keys are limited to a maximum depth of 200 underscore-separated segments to prevent CPU-exhaustion denial-of-service attacks. Additionally, the library now supports configuring \NULLS FIRST\ and \NULLS LAST\ behavior for sort orders across different database dialects.
lib/ransack · high confidence
Introduce RuboCop linting and modernize development workflow
The project now enforces code style and quality using RuboCop (targeting Ruby 3.2), with a new \.rubocop.yml\ configuration and updated \Rakefile\ tasks (\test\, \test\_pg\, \test\_mysql\, \test\_all\, \test\_detected\) that run both RuboCop and RSpec. The default rake task now runs the combined test suite, and the development console has switched from IRB to Pry. Documentation has moved to a Jekyll/Just the Docs site, replacing the old README.rdoc, and the repository structure has been cleaned up (e.g., removing the old spec file and adding a \.nojekyll\ marker).
(repo-wide) · high confidence
Lazy-load Rails integration helpers via ActiveSupport hooks
Ransack now defers loading its Action Controller and Active Record adapters until the respective frameworks are ready, using \ActiveSupport.on\_load\ hooks instead of requiring them immediately at startup. This change improves application boot times and compatibility by ensuring dependencies like \ActionController::Base\ and \ActiveRecord::Base\ are fully loaded before Ransack attempts to extend them, while also introducing a dedicated deprecator for version 7.0.
lib · high confidence
Refactored search nodes to support ransacker arguments, aliases, and strict validation
The search node architecture has been refactored to improve binding, validation, and extensibility. Attribute and Sort nodes now include the new Bindable module, enabling proper resolution of attribute aliases and support for ransacker arguments (ransacker\_args). The Condition node now accepts ransacker\_args when building attributes and validates them against the context. Grouping nodes have replaced the separate And/Or classes with a unified Groupings collection, and combinator handling is now centralized in the Node base class, raising an InvalidSearchError for invalid or mixed combinators in strict mode. Value casting has been simplified to use a single value attribute and now includes support for PostgreSQL money and timestamptz types, as well as improved handling of Date-to-Time conversions.
lib/ransack/nodes · high confidence
Removed direct Active Record adapter entry point
The \lib/ransack/adapters/active\_record.rb\ file has been removed, eliminating the direct entry point that previously required the base and context adapter files. This change aligns with the project's move toward ORM agnosticism, where Active Record adapters are loaded only if Active Record is already defined, rather than being forcibly required by the adapter file itself.
lib/ransack/adapters · high confidence
Test coverage
Added test coverage for Ransack node value casting, condition handling, and grouping logic; Added test coverage for Ransack search key depth limits and configuration options; Added test coverage for Ransack's ActiveRecord adapter integration; Expanded test coverage for Ransack form helpers; Expanded test suite with multi-database support and new model features; Migrate test data generation from Blueprints to FactoryBot; Migrate test suite from Machinist to FactoryBot; Remove obsolete ActiveRecord adapter specs.
Dependencies
Upgrade to Rails 7.2+ and modernize documentation tooling
The gem now requires Ruby 3.2+ and Active Record 7.2+, dropping support for older Rails and Ruby versions. The documentation site has been migrated from Docusaurus to Jekyll with the Just the Docs theme, and the main Gemfile now uses HTTPS for RubyGems and Rails sources, adds explicit dependencies for sqlite3 (\>= 2.9.5 to address [CVE redacted]), pg, mysql2, and trilogy, and updates test dependencies to factory\_bot and RSpec 3.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 51 → 68 (+17.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 95 (-4.9)
- Architecture 92 → 96 (+4.6)
- Maturity 53 → 61 (+7.7)
- Readiness 34 → 67 (+33.4)
- Security 65 → 72 (+7.0)
Resolved (36)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 16 more
New (66)
- Ambiguous distinction between ransack and ransack! without clear documentation of behavioral difference (e.g., strictness vs. lazy loading). In many ORMs, the bang variant implies raising errors on invalid input, but here it is unclear if it differs from the non-bang version in validation strictness or just return type.
- Context.evaluate (cognitive 16) (lib/ransack/active_record/context.rb)
- Context.extract_correlated_key (cognitive 17) (lib/ransack/active_record/context.rb)
- Documentation: contradicts the code (docs/going-further/polymorphic-search.md)
- Documentation: no architecture or design documentation (docs/going-further/custom-predicates.md)
- Documentation: no architecture or design documentation (docs/going-further/exporting-to-csv.md)
- Duplicate method name dialect exists on both the generic Ransack::Context and the adapter-specific Ransack::ActiveRecord::Context. While this is likely an override, the presence of the method in the base context suggests it might be a generic interface, yet the implementation details are heavily tied to ActiveRecord. This creates confusion about whether dialect is a core abstraction or an adapter-specific concern.
- FixmeComment (spec/ransack/helpers/form_builder_spec.rb)
- FixmeComment (spec/ransack/helpers/form_helper_spec.rb)
- Floating git dependency: actionpack
- Floating git dependency: activemodel
- Floating git dependency: activerecord
- Floating git dependency: activesupport
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 46 more
Changes since last survey
- 49 commits — 42 feature/other, 7 fixes
By area
- lib/ransack — 26 commits
- docs/docs — 9 commits
- (root) — 4 commits
- .github/workflows — 3 commits
- spec/ransack — 3 commits
- docs/getting-started — 2 commits
- (repo) — 1 commit
- docs/going-further — 1 commit
Notable commits
- fix: Fix ActiveModel::RangeError across multiple attributes in one condition (#1691)
- fix: Fix deprecation warning from arel_extensions >= 2.2 in extract_correlated_key (#1679)
- fix: Fix issue with ransackable_attribute not handling symbols correctly (#1539)
- fix: Fix low-level c: API silently dropping conditions when a:/v: are arrays of envelope hashes (#1150) (#1675)
- fix: Fix ten small, self-contained bugs from the issue triage (#1708)
- fix: Fix the nightly Rails-main job and make it runnable on demand (#1702)
- fix: Revert "Version 4.5.0 (#1684)"
- change: Add NULL FIRST and NULL LAST for most databases (#1696)
- change: Add i_start and i_end, the case-insensitive start and end predicates (#1716)
- change: Add ignore_blank_values config option (#1683)
- change: Add length predicates for searching by string length (#1697)
- change: Add support for the Trilogy adapter (#1698)
- change: Allow nested groupings (longhand) to be passed (#1430)
- change: Allow nil values in array (#1657)
- change: Cast SQLServer's :datetimeoffset to time (#1689)
- change: Detect the SQL dialect from the adapter class; drop the PostGIS dependency (#1707)
- change: Document behaviour shipping in 4.5.0 (#1695)
- change: Document the release flow now that publishing is automatic (#1704)
- change: Document what the issue triage found already answered (#1712)
- change: Drop Ruby 3.1 support (#1705)
- …and 29 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
activerecord-hackery/ransack was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3a173ad90eb63e6b1dc24e2b4414b917d785f388 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.