Skip to content
CAI
Software that uses CAICheck a score

ankane/lockbox

69.8

Adequate · 19 September 2026

1.7k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Ruby gem that provides transparent encryption for ActiveRecord and Mongoid models, supporting both standard and hybrid encryption algorithms. It enables secure handling of sensitive data fields and encrypted file uploads via Active Storage, CarrierWave, and Shrine. The library includes utilities for key rotation, data migration, and auditing access to encrypted records, while maintaining compatibility with modern Rails and Ruby versions.

Features

Added Lockbox audit trail generator

The library now includes a generator for creating an audit trail to track access to encrypted data. This adds a new \LockboxAudit\ model and a corresponding database migration that stores polymorphic references to the encrypted record (\subject\) and the user who viewed it (\viewer\), along with the encrypted \data\, a \context\ string, an \ip\ address, and a \created\_at\ timestamp. The model includes JSON serialization for the data field when the underlying database column type is text.

lib/generators/lockbox, lib/generators/lockbox/templates · high confidence

Behavioural changes

Lockbox 2.2 requires Active Record 7.2+ and Ruby 3.3+, dropping older versions

This release enforces stricter version requirements for supported frameworks and languages. The library now raises an error if used with Active Record versions below 7.2 or Mongoid versions below 8, and it requires Ruby 3.3 or higher. This change removes support for older Active Record and Mongoid versions, as well as Ruby versions below 3.3, to align with current maintenance standards and ensure compatibility with the latest features.

lib · high confidence

Lockbox 2.2.0: Major rewrite with hybrid encryption, pluck support, and Active Storage integration

Lockbox has been rewritten as a module and upgraded to version 2.2.0, introducing hybrid encryption support (Curve25519) alongside existing algorithms, and adding support for the \pluck\ method to efficiently retrieve and decrypt encrypted columns. The gem now integrates with Active Storage via \CreateOne\ and \Attachment\ extensions to handle encrypted file uploads and downloads, and includes a new \Migrator\ class to facilitate data migration and key rotation. Configuration has shifted to use \has\_encrypted\ instead of \encrypts\, and the library now supports Rails credentials for master key management.

lib/lockbox · high confidence

Test coverage

Added test support fixtures for ActiveRecord, Mongoid, CarrierWave, Shrine, and Action Text; Expanded test coverage for encryption, migration, and file storage features; Expanded test database schema for comprehensive encryption coverage; Removed test fixture model User.

Dependencies

Add CI gemfiles for Rails 7.2, Rails 8.0, Mongoid 8, and Mongoid 9

New isolated gemfiles have been added to the gemfiles directory to enable testing against Rails 7.2.0, Rails 8.0.0, Mongoid 8, and Mongoid 9. These files define specific dependency constraints (such as carrierwave \~\> 2 or \~\> 3 and json \< 3) and database adapters (including trilogy) required to validate compatibility with these newer versions of Rails and the Mongoid ODM.

gemfiles · high confidence

Updated dependencies and raised minimum Ruby version to 3.3

The project now requires Ruby 3.3 or higher, dropping support for older versions. Development dependencies have been consolidated into the Gemfile, specifying Rails 8.1.0, CarrierWave \~\> 3, and database adapters including sqlite3, pg, mysql2, and trilogy. Additional test dependencies such as minitest, nokogiri, ruby-vips, combustion, rbnacl, shrine, and json (\< 3) are now explicitly listed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 70.

Lenses

  • Code Health 85
  • Architecture 100
  • Maturity 59
  • Readiness 67
  • Security 99

Changes since last survey

  • 300 commits — 240 feature/other, 60 fixes

By area

  • (root) — 132 commits
  • lib/lockbox — 46 commits
  • .github/workflows — 24 commits
  • test/model_test.rb — 23 commits
  • test/model_types_test.rb — 12 commits
  • test/support — 12 commits
  • docs/Compatibility.md — 11 commits
  • lib/lockbox.rb — 8 commits
  • test/active_storage_test.rb — 8 commits
  • test/action_text_test.rb — 5 commits
  • gemfiles/rails72.gemfile — 4 commits
  • test/insert_test.rb — 4 commits
  • test/pluck_test.rb — 4 commits
  • gemfiles/rails70.gemfile — 2 commits
  • test/lockbox_test.rb — 2 commits
  • gemfiles/rails71.gemfile — 1 commit
  • test/internal — 1 commit
  • test/migrate_test.rb — 1 commit

Notable commits

  • fix: Fix issue where edge rails removes write_attribute_without_type_cast and implements default variants (#103)
  • fix: Fix year for 0.6.2 (#108)
  • fix: Fixed Action Text deserialization with Rails 7.1 - fixes #183
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed CI
  • fix: Fixed [] method for encrypted attributes - fixes #82
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ankane/lockbox was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9cabaee26d9d70fb5007121033ac902aebe8a438 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.