Skip to content
CAI
Software that uses CAICheck a score

ankane/chartkick

58.4

Adequate · 26 September 2026

204

lines of production code

Ruby

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Chartkick library, a Ruby gem that provides helper methods for rendering various chart types such as line, pie, and bar charts. It integrates with the Chart.js JavaScript library to handle the actual visualization and supports modern web frameworks like Rails and Sinatra. The system ensures security compliance through Content Security Policy nonce support and manages asset delivery via importmaps and Sprockets.

Removals

Removal of legacy Chartkick.js implementation

The legacy \app/assets/javascripts/chartkick.js\ file has been removed. This file contained a custom, self-contained implementation of Chartkick that relied exclusively on Google Charts to render Line, Pie, and Column charts. Its removal indicates that the application no longer supports this specific bundled JavaScript library, likely shifting to a different charting solution or a newer version of the library managed elsewhere.

app/assets · high confidence

Behavioural changes

Chartkick upgraded to v5.2.1 with CSP nonce support and importmap compatibility

This update upgrades the Chartkick library to version 5.2.1, introducing significant changes to how charts are rendered and integrated. The helper methods now support Content Security Policy (CSP) nonces, automatically detecting and applying nonces from Rails 5.2+ or Secure Headers to script tags, which improves security compliance. Additionally, the engine has been updated to support importmap-rails by conditionally adding assets to the precompile list only when both Importmap and Sprockets are defined, while also adding new core extensions for JSON serialization and utility functions for deep merging and JSON escaping. The version bump reflects these structural and security enhancements.

lib/chartkick · high confidence

Support for Sinatra, global options, and safer ActiveSupport loading

Chartkick now supports Sinatra applications in addition to Rails, with the Sinatra integration loaded only when the framework is detected. The library introduces global configuration options accessible via \Chartkick.options\ and a new \content\_for\ setting to control how JavaScript assets are rendered. Additionally, the initialization logic has been updated to safely include the helper module using \ActiveSupport.on\_load\, preventing exceptions if ActiveSupport is only partially loaded.

lib · high confidence

Test coverage

Initial test suite for Chartkick helper methods

Added a new test suite (\test/chartkick\_test.rb\) covering the core chart helper methods (line, pie, column, bar, area, scatter, geo, timeline) and validating key behaviors such as data escaping to prevent XSS, option immutability, width/height validation, nonce injection, deferred loading deprecation, content\_for support, default options, automatic chart ID generation, and JSON serialization.

test · high confidence

Dependencies

Updated Chart.js to 4.5.1 and modernized Ruby gem configuration

The JavaScript build now uses Chart.js 4.5.1 (along with @kurkle/color 0.3.2, chartjs-adapter-date-fns 3.0.0, and date-fns 2.30.0) via a new build/package.json, replacing the previous bundling approach. On the Ruby side, the gemspec has been cleaned up to specify a single author and email, set the homepage to https://chartkick.com, restrict the required Ruby version to \>= 3.2, and move development dependencies (minitest, rake) into the Gemfile.

(dependencies) · high confidence

Updated Chart.js to v4.5.1

The build process now bundles Chart.js version 4.5.1 (along with @kurkle/color v0.3.2, chartjs-adapter-date-fns v3.0.0, and date-fns v2.30.0) into the vendor JavaScript file. This upgrade brings the latest features and fixes from the Chart.js 4.x series to the application's charting capabilities.

build · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 58 (+10.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 96 (-0.4)
  • Architecture 69 → 69 (+0.0)
  • Maturity 55 → 39 (-16.4)
  • Readiness 26 → 70 (+43.8)
  • Security 90 → 100 (+9.8)

Resolved (8)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Scanner failed to run — not a clean result
  • Test reliability not included

New (8)

  • Helper.chartkick_chart (cognitive 23) (lib/chartkick/helper.rb)
  • Helper.chartkick_chart (cyclomatic 19) (lib/chartkick/helper.rb)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No dependency advisory monitoring
  • Scanner failed to run — not a clean result
  • Scanner failed to run — not a clean result
  • Workflow token permissions not restricted

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • .github/workflows — 1 commit

Notable commits

  • change: Updated checkout action [skip ci]

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ankane/chartkick was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2c6cd4eb6275021c7b87d8e52767cde3bec396d2 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.