ankane/chartkick
58.4
Adequate · 26 September 2026
204
lines of production code
Ruby
with JavaScript
4
measurements over time
What this system is
This system is the Chartkick library, a Ruby gem that provides helper methods for rendering various chart types such as line, pie, and bar charts. It integrates with the Chart.js JavaScript library to handle the actual visualization and supports modern web frameworks like Rails and Sinatra. The system ensures security compliance through Content Security Policy nonce support and manages asset delivery via importmaps and Sprockets.
Removals
Removal of legacy Chartkick.js implementation
The legacy \app/assets/javascripts/chartkick.js\ file has been removed. This file contained a custom, self-contained implementation of Chartkick that relied exclusively on Google Charts to render Line, Pie, and Column charts. Its removal indicates that the application no longer supports this specific bundled JavaScript library, likely shifting to a different charting solution or a newer version of the library managed elsewhere.
app/assets · high confidence
Behavioural changes
Chartkick upgraded to v5.2.1 with CSP nonce support and importmap compatibility
This update upgrades the Chartkick library to version 5.2.1, introducing significant changes to how charts are rendered and integrated. The helper methods now support Content Security Policy (CSP) nonces, automatically detecting and applying nonces from Rails 5.2+ or Secure Headers to script tags, which improves security compliance. Additionally, the engine has been updated to support importmap-rails by conditionally adding assets to the precompile list only when both Importmap and Sprockets are defined, while also adding new core extensions for JSON serialization and utility functions for deep merging and JSON escaping. The version bump reflects these structural and security enhancements.
lib/chartkick · high confidence
Support for Sinatra, global options, and safer ActiveSupport loading
Chartkick now supports Sinatra applications in addition to Rails, with the Sinatra integration loaded only when the framework is detected. The library introduces global configuration options accessible via \Chartkick.options\ and a new \content\_for\ setting to control how JavaScript assets are rendered. Additionally, the initialization logic has been updated to safely include the helper module using \ActiveSupport.on\_load\, preventing exceptions if ActiveSupport is only partially loaded.
lib · high confidence
Test coverage
Initial test suite for Chartkick helper methods
Added a new test suite (\test/chartkick\_test.rb\) covering the core chart helper methods (line, pie, column, bar, area, scatter, geo, timeline) and validating key behaviors such as data escaping to prevent XSS, option immutability, width/height validation, nonce injection, deferred loading deprecation, content\_for support, default options, automatic chart ID generation, and JSON serialization.
test · high confidence
Dependencies
Updated Chart.js to 4.5.1 and modernized Ruby gem configuration
The JavaScript build now uses Chart.js 4.5.1 (along with @kurkle/color 0.3.2, chartjs-adapter-date-fns 3.0.0, and date-fns 2.30.0) via a new build/package.json, replacing the previous bundling approach. On the Ruby side, the gemspec has been cleaned up to specify a single author and email, set the homepage to https://chartkick.com, restrict the required Ruby version to \>= 3.2, and move development dependencies (minitest, rake) into the Gemfile.
(dependencies) · high confidence
Updated Chart.js to v4.5.1
The build process now bundles Chart.js version 4.5.1 (along with @kurkle/color v0.3.2, chartjs-adapter-date-fns v3.0.0, and date-fns v2.30.0) into the vendor JavaScript file. This upgrade brings the latest features and fixes from the Chart.js 4.x series to the application's charting capabilities.
build · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 48 → 58 (+10.5)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 97 → 96 (-0.4)
- Architecture 69 → 69 (+0.0)
- Maturity 55 → 39 (-16.4)
- Readiness 26 → 70 (+43.8)
- Security 90 → 100 (+9.8)
Resolved (8)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- No tests found
- Scanner failed to run — not a clean result
- Test reliability not included
New (8)
- Helper.chartkick_chart (cognitive 23) (lib/chartkick/helper.rb)
- Helper.chartkick_chart (cyclomatic 19) (lib/chartkick/helper.rb)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No dependency advisory monitoring
- Scanner failed to run — not a clean result
- Scanner failed to run — not a clean result
- Workflow token permissions not restricted
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- .github/workflows — 1 commit
Notable commits
- change: Updated checkout action [skip ci]
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ankane/chartkick was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 2c6cd4eb6275021c7b87d8e52767cde3bec396d2 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.