Skip to content
CAI
Software that uses CAICheck a score

danielberkompas/cloak_ecto

48.0

Weak · 18 September 2026

1.4k

lines of production code

Elixir

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a library for Ecto that provides encryption and hashing capabilities for database fields. It supports a wide variety of data types, including dates, decimals, and complex structures, and offers features like lazy evaluation for large payloads. The library also includes tools for migrating existing data and rotating encryption keys safely.

Features

Add release, changelog, and CI test scripts

New executable scripts have been added to the bin directory to streamline the release process and continuous integration. The bin/release script automates the generation of the changelog, git tagging, and publishing to Hex. The bin/changelog script provides a direct way to generate changelogs for future releases. Additionally, bin/test standardizes the CI workflow by handling code formatting checks, compilation with warnings as errors, and running tests or coverage reports depending on the environment.

bin · high confidence

New Ecto field types for Date, DateTime, Time, NaiveDateTime, Decimal, Float, Integer, Binary, and Lists

The library now provides dedicated Ecto types for encrypting a wide range of data formats beyond simple strings. Users can now encrypt Date, DateTime, Time, and NaiveDateTime fields, which are serialized to strings before encryption and parsed back upon decryption. Additionally, new types support Decimal (for high-precision values), Float, Integer, and Binary fields. Support for complex structures has been added via StringList, IntegerList, and Map types, which serialize data to JSON using the configured JSON library before encryption. These new types allow Cloak to handle diverse schema requirements directly within Ecto migrations and schemas.

_lib/cloak\ecto/types · high confidence

New mix task for proactive encryption key rotation

A new \mix cloak.migrate.ecto\ task has been added to proactively reencrypt database records with a new encryption key, allowing you to decommission old keys. The task pages through tables using a cursor (defaulting to the primary key, with support for custom cursor fields via the \Cloak.CustomCursor\ behavior) and updates rows in parallel to maximize speed. Configuration can be provided via command-line flags (\-r\ for repo, \-s\ for schema) or application config (\cloak\_repo\ and \cloak\_schemas\).

_lib/cloak\ecto/migrator, lib/mix · high confidence

Behavioural changes

Migrate to Elixir 1.10+ config syntax and add test configuration

The application configuration has been updated to use the modern \import Config\ syntax instead of the deprecated \Mix.Config\, aligning with Elixir 1.10+ standards. A new \config/test.exs\ file has been introduced to define environment-specific settings for testing, including the JSON library, encryption ciphers for \Cloak.Ecto\, and the Ecto repositories. The main \config/config.exs\ now conditionally imports this test configuration only when the environment is set to \:test\.

config · high confidence

Removal of placeholder API and documentation in Cloak.Ecto

The Cloak.Ecto module has been cleaned up by removing the placeholder \hello/0\ function and its associated documentation, which are no longer part of the public API. The module's documentation attribute is now set to false, indicating that this module does not expose user-facing documentation or functionality in its current state.

lib · high confidence

Support for closure-wrapped values and improved migration robustness

The Cloak.Ecto.Type macro now supports a \:closure\ option, allowing encrypted fields to return lazy functions instead of immediate values upon loading, which can improve performance for large payloads. The \equal?\ implementation has been updated to unwrap these closures before comparison. Additionally, the new \Cloak.Ecto.Migrator\ module provides a safer way to migrate existing data, utilizing \Task.async\_stream\ for concurrency and correctly handling complex field types such as \Ecto.Enum\, arrays, and maps. A new \Cloak.Ecto.Crypto\ interface abstracts HMAC calls to support both modern and legacy OTP versions.

_lib/cloak\ecto · high confidence

Test coverage

Added test coverage for Cloak.Ecto types with closure support; Added test support infrastructure for Cloak.Ecto; Added test support modules for binary and HMAC types; Added tests for the Ecto migration functionality; Updated test suite initialization and removed obsolete test.

Dependencies

Release Cloak.Ecto 1.3.0 with updated dependencies

This release bumps the library version to 1.3.0 and updates the dependency tree, pinning \cloak\ to \~\> 1.1.1 and \ecto\ to \~\> 3.0. It introduces \castore\ for test mode, adds \pbkdf2\ from a specific GitHub fork (miniclip/erlang-pbkdf2) to support Erlang 24, and includes development dependencies like \ex\_doc\, \excoveralls\, \ecto\_sql\, \postgrex\, \jason\, and \inch\_ex\. The project metadata is also updated with source URLs, package details, and documentation configuration.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 48.

Lenses

  • Code Health 100
  • Architecture 69
  • Maturity 35
  • Readiness 38
  • Security 94

Changes since last survey

  • 89 commits — 82 feature/other, 7 fixes

By area

  • (root) — 42 commits
  • (repo) — 18 commits
  • lib/cloak_ecto — 12 commits
  • test/support — 5 commits
  • guides/how_to — 3 commits
  • .semaphore/semaphore.yml — 2 commits
  • guides/upgrading — 2 commits
  • bin/changelog — 1 commit
  • bin/release — 1 commit
  • bin/test — 1 commit
  • config/config.exs — 1 commit
  • config/test.exs — 1 commit

Notable commits

  • fix: :bug: Add support for {:array, inner_type} fields
  • fix: :bug: Add support for {:map, inner_type} fields
  • fix: :pencil: Document fix for :default values
  • fix: :pencil: Fix README on docker
  • fix: :recycle: Fix compiler warning, improve logic
  • fix: Fix Cloak.Ecto.SHA256, make embed_as/equal? overridable
  • fix: 🐛 Fix Migrator when schema contains Ecto.Enum
  • change: :arrow_up: Upgrade dockerfile to Elixir 1.13, Erlang 25
  • change: :arrow_up: Upgrade local dependencies
  • change: :heavy_plus_sign: Add InchCI library for badge
  • change: :memo: Add badges to README
  • change: :memo: Adding docs from cloak repo
  • change: :page_facing_up: Add license
  • change: :pencil: Document that :ciphers is order-dependent
  • change: :pencil: Recommend HMAC over SHA256
  • change: :recycle: Extract code from Cloak
  • change: :rocket: Add bin/release script
  • change: :tada: init
  • change: :white_check_mark: Build against Erlang 25
  • change: :white_check_mark: Improve test coverage
  • …and 69 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

danielberkompas/cloak_ecto was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9989e732c8211c6d867fcd2f2c4843912b24fc8d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.