attr-encrypted/attr_encrypted
59.8
Adequate · 19 September 2026
588
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is the attr\_encrypted Ruby gem, a library for encrypting model attributes that integrates with ActiveRecord and Sequel. It provides secure encryption with per-attribute initialization vectors and salts while maintaining backward compatibility with legacy single-IV modes. The gem handles attribute dirty tracking, virtual attribute management, and data integrity verification through checksums.
Features
Added SHA-256 and SHA-512 checksums for attr\_encrypted versions 3.0.0 through 3.1.0
Checksum files (SHA-256 and SHA-512) have been added for the attr\_encrypted gem versions 3.0.0, 3.0.1, 3.0.2, 3.0.3, and 3.1.0. This allows users to verify the integrity of these specific gem releases.
checksum · high confidence
New ActiveRecord and Sequel adapters for encrypted attributes
The library now includes dedicated adapters for ActiveRecord and Sequel, enabling seamless integration with these ORMs. The ActiveRecord adapter ensures encrypted virtual attributes are correctly invalidated on reload, supports dynamic query methods (like find\_by\_email) for single\_iv\_and\_salt mode, and properly handles attribute dirtiness and assignment order to work with modern Rails versions (3.1+). The Sequel adapter provides basic extension support for Sequel models.
_lib/attr\encrypted/adapters · high confidence
Removals
Removal of legacy Active Record and Object encryption integrations
The legacy Active Record integration module (lib/huberry/active\_record.rb) and the core Object/Class encryption logic (lib/huberry/class.rb, lib/huberry/object.rb) have been removed. This eliminates the previous implementation that used method aliasing for Active Record and direct class method definitions for generic objects, effectively stripping out the core encryption functionality previously provided by these specific files.
lib/huberry · high confidence
Behavioural changes
Major refactor: new namespace, encryption modes, and per-attribute IVs
The library has been rewritten to use the \AttrEncrypted\ module instead of polluting the global \Object\ and \Class\ namespaces, and it now relies on the \encryptor\ gem rather than the deprecated \huberry\ gem. Users benefit from stronger security defaults, including per-attribute initialization vectors (IVs) and salts, and a new \mode\ option that allows switching between the new secure defaults and the legacy \:single\_iv\_and\_salt\ behavior for compatibility. The API also introduces an \attr\_encryptor\ alias for \attr\_encrypted\ and adds options like \allow\_empty\_value\ to control encryption of empty strings.
lib · high confidence
Test coverage
Added comprehensive test suite for legacy and new encryption modes
Added a new set of tests to verify backwards compatibility and correct behavior across different encryption configurations. The suite includes \compatibility\_test.rb\ and \legacy\_compatibility\_test.rb\ to ensure that data encrypted with older modes (single IV and salt) can be correctly decrypted by the new per-attribute IV and salt mode, and vice versa. It also adds \legacy\_active\_record\_test.rb\, \legacy\_sequel\_test.rb\, and updated \active\_record\_test.rb\ and \sequel\_test.rb\ to cover encryption, marshaling, encoding, and validation behaviors for both legacy and current ORM adapters.
test · high confidence
Dependencies
Initial gemspec and Gemfile setup with Ruby 2.7+ requirement
The project now includes a Gemfile and a gemspec that define the package structure and dependencies. The library requires Ruby version 2.7.0 or higher and depends on the 'encryptor' gem (version \~3.0.0). Development dependencies include ActiveRecord (\>= 6.0.0), ActionPack, Rake, Minitest, Sequel, Pry, and SimpleCov, with specific SQLite3 adapter versions configured for JRuby and different ActiveRecord versions. A post-install warning informs users that the \\#encrypted\_attributes\ method is deprecated in favor of \\#attr\_encrypted\_encrypted\_attributes\ to avoid conflicts with Active Record 7 native encryption.
(dependencies) · high confidence
Housekeeping
Version bump to 4.2.0
The gem version has been updated to 4.2.0, as reflected in the new version.rb file defining MAJOR 4, MINOR 2, and PATCH 0.
_lib/attr\encrypted · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 60.
Lenses
- Code Health 99
- Architecture 69
- Maturity 46
- Readiness 62
- Security 96
Changes since last survey
- 300 commits — 262 feature/other, 38 fixes
By area
- (root) — 104 commits
- (repo) — 61 commits
- lib/attr_encrypted — 51 commits
- lib/attr_encrypted.rb — 31 commits
- test/active_record_test.rb — 22 commits
- test/test_helper.rb — 9 commits
- test/attr_encrypted_test.rb — 4 commits
- test/compatibility_test.rb — 4 commits
- .github/workflows — 2 commits
- certs/saghaulor.pem — 2 commits
- test/legacy_active_record_test.rb — 2 commits
- checksum/attr_encrypted-3.0.0.gem.sha256 — 1 commit
- checksum/attr_encrypted-3.0.1.gem.sha256 — 1 commit
- checksum/attr_encrypted-3.0.2.gem.sha256 — 1 commit
- checksum/attr_encrypted-3.0.3.gem.sha256 — 1 commit
- checksum/attr_encrypted-3.1.0.gem.sha256 — 1 commit
- test/data_mapper_test.rb — 1 commit
- test/debug_order.rb — 1 commit
- test/legacy_compatibility_test.rb — 1 commit
Notable commits
- fix: Fix CI failures for Rails 6.0 to 7.0.
- fix: Fix SystemStackError when extending the reload method with Module#prepend (#457)
- fix: Fix attr_was method.
- fix: Fix bundler warning
- fix: Fix evaluation of private options.
- fix: Fix mass assignment protection in Rails 4
- fix: Fix minitest guard for rails 4 breaking specs (#448)
- fix: Fix-up of merged tests from attr_encryptor
- fix: Fixed ActiveModel::Dirty methods.
- fix: Fixed an issue where specifying more than one attribute on the same line resulting in all of them having the same :attribute value in the options hash
- fix: Fixed bug where we were comparing versions as strings (#419)
- fix: Fixed dependency conflict for MRI 2.1.x builds
- fix: Fixed failing tests.
- fix: Fixed issue where IV and salt are generated when encrypted attrribute value is empty
- fix: Fixed tests to use correct key length
- fix: Fixed the ActiveRecord adapter to only look up column names when the table exists.
- fix: Fixes #118 Documentation database columns required for "per attribute IV and salt" encryption mode
- fix: Fixes #68 Overload ActiveRecord::Base.reload to invalidate all encrypted virtual attributes
- fix: Fixes defect in which encrypted_attributes state was shared across all instances of a given class due to shallow dup. This caused random OpenSSL::Cipher::CipherError errors, particularly in cases in which concurrent encrypts/decrypts were occurring.
- fix: Fixes to unit tests and updates to configuration to support CI builds using Travis CI
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
attr-encrypted/attr_encrypted was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e8c9e2ff22d93e645f5957d314c44fa28ecf2f9e — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.