ankane/lockbox
69.8
Adequate · 19 September 2026
1.7k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is a Ruby gem that provides transparent encryption for ActiveRecord and Mongoid models, supporting both standard and hybrid encryption algorithms. It enables secure handling of sensitive data fields and encrypted file uploads via Active Storage, CarrierWave, and Shrine. The library includes utilities for key rotation, data migration, and auditing access to encrypted records, while maintaining compatibility with modern Rails and Ruby versions.
Features
Added Lockbox audit trail generator
The library now includes a generator for creating an audit trail to track access to encrypted data. This adds a new \LockboxAudit\ model and a corresponding database migration that stores polymorphic references to the encrypted record (\subject\) and the user who viewed it (\viewer\), along with the encrypted \data\, a \context\ string, an \ip\ address, and a \created\_at\ timestamp. The model includes JSON serialization for the data field when the underlying database column type is text.
lib/generators/lockbox, lib/generators/lockbox/templates · high confidence
Behavioural changes
Lockbox 2.2 requires Active Record 7.2+ and Ruby 3.3+, dropping older versions
This release enforces stricter version requirements for supported frameworks and languages. The library now raises an error if used with Active Record versions below 7.2 or Mongoid versions below 8, and it requires Ruby 3.3 or higher. This change removes support for older Active Record and Mongoid versions, as well as Ruby versions below 3.3, to align with current maintenance standards and ensure compatibility with the latest features.
lib · high confidence
Lockbox 2.2.0: Major rewrite with hybrid encryption, pluck support, and Active Storage integration
Lockbox has been rewritten as a module and upgraded to version 2.2.0, introducing hybrid encryption support (Curve25519) alongside existing algorithms, and adding support for the \pluck\ method to efficiently retrieve and decrypt encrypted columns. The gem now integrates with Active Storage via \CreateOne\ and \Attachment\ extensions to handle encrypted file uploads and downloads, and includes a new \Migrator\ class to facilitate data migration and key rotation. Configuration has shifted to use \has\_encrypted\ instead of \encrypts\, and the library now supports Rails credentials for master key management.
lib/lockbox · high confidence
Test coverage
Added test support fixtures for ActiveRecord, Mongoid, CarrierWave, Shrine, and Action Text; Expanded test coverage for encryption, migration, and file storage features; Expanded test database schema for comprehensive encryption coverage; Removed test fixture model User.
Dependencies
Add CI gemfiles for Rails 7.2, Rails 8.0, Mongoid 8, and Mongoid 9
New isolated gemfiles have been added to the gemfiles directory to enable testing against Rails 7.2.0, Rails 8.0.0, Mongoid 8, and Mongoid 9. These files define specific dependency constraints (such as carrierwave \~\> 2 or \~\> 3 and json \< 3) and database adapters (including trilogy) required to validate compatibility with these newer versions of Rails and the Mongoid ODM.
gemfiles · high confidence
Updated dependencies and raised minimum Ruby version to 3.3
The project now requires Ruby 3.3 or higher, dropping support for older versions. Development dependencies have been consolidated into the Gemfile, specifying Rails 8.1.0, CarrierWave \~\> 3, and database adapters including sqlite3, pg, mysql2, and trilogy. Additional test dependencies such as minitest, nokogiri, ruby-vips, combustion, rbnacl, shrine, and json (\< 3) are now explicitly listed.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 70.
Lenses
- Code Health 85
- Architecture 100
- Maturity 59
- Readiness 67
- Security 99
Changes since last survey
- 300 commits — 240 feature/other, 60 fixes
By area
- (root) — 132 commits
- lib/lockbox — 46 commits
- .github/workflows — 24 commits
- test/model_test.rb — 23 commits
- test/model_types_test.rb — 12 commits
- test/support — 12 commits
- docs/Compatibility.md — 11 commits
- lib/lockbox.rb — 8 commits
- test/active_storage_test.rb — 8 commits
- test/action_text_test.rb — 5 commits
- gemfiles/rails72.gemfile — 4 commits
- test/insert_test.rb — 4 commits
- test/pluck_test.rb — 4 commits
- gemfiles/rails70.gemfile — 2 commits
- test/lockbox_test.rb — 2 commits
- gemfiles/rails71.gemfile — 1 commit
- test/internal — 1 commit
- test/migrate_test.rb — 1 commit
Notable commits
- fix: Fix issue where edge rails removes write_attribute_without_type_cast and implements default variants (#103)
- fix: Fix year for 0.6.2 (#108)
- fix: Fixed Action Text deserialization with Rails 7.1 - fixes #183
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed CI
- fix: Fixed [] method for encrypted attributes - fixes #82
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ankane/lockbox was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9cabaee26d9d70fb5007121033ac902aebe8a438 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.