Skip to content
CAI
Software that uses CAICheck a score

shrinerb/shrine

60.5

Adequate · 28 September 2026

7.3k

lines of production code

Ruby

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Shrine gem, a Ruby library designed for flexible and efficient file attachment and processing. It provides a plugin-based architecture that supports various storage backends, such as S3 and local file systems, along with features like background job processing, on-the-fly image derivation, and metadata management. The repository also includes a Roda-based demo application that showcases these capabilities through a complete album and photo management workflow, alongside automated documentation and testing infrastructure.

How it got here

2015 — Shrine 3.0 major release and refactoring

11 changes.

This period marks the major version 3.0 release of the library, involving a rename from Uploadie to Shrine and a comprehensive architectural refactor. The work focused on extracting core logic into dedicated plugins, rewriting storage implementations, and establishing a new, robust test suite using Minitest::Spec to ensure stability across the updated API.

2016–2017 — Roda/Sequel demo application

11 changes.

The project introduced a new demo application built with Roda and Sequel to replace the previous Rails-based example. This update implemented a modern file upload workflow using Uppy for direct-to-S3 uploads, background job processing with SuckerPunch, and dynamic image derivation. The work included full database migrations, model definitions, and acceptance tests to showcase advanced Shrine integration patterns.

2019–2024 — Documentation site modernization

5 changes.

The project modernized its documentation website by migrating to Docusaurus 3, introducing a redesigned home page with demo snippets and sponsor showcases, and implementing automated deployment scripts. Concurrently, integration tests were added to ensure the backgrounding plugin functions correctly with both ActiveRecord and Sequel ORMs.

Features

Add Roda and Sequel demo models for image uploads

The demo application now includes model definitions for Album and Photo using the Sequel ORM, demonstrating how to integrate image uploads with the derivatives plugin. The Album model establishes a one-to-many relationship with photos, manages nested attributes, and includes a cover photo attachment, while the Photo model handles individual image attachments.

demo/models · high confidence

Added CNAME file for custom domain configuration

A CNAME file containing 'shrinerb.com' has been added to the website static assets, enabling the hosting platform to correctly map the custom domain to the site.

website/static · high confidence

Added database migrations for albums and photos in the demo app

The demo application now includes database migration files to set up the schema for albums and photos. These migrations create an 'albums' table with name and cover photo data fields, and a 'photos' table linked to albums via a foreign key, including title and image data fields to support file storage via Shrine.

demo/db · high confidence

Automated website publishing script

A new executable script at bin/publish has been added to automate the deployment of the website. Running this script builds the site using npm, switches to the gh-pages branch, copies the built files, commits the changes with the message 'Update website', pushes to the remote repository, and finally switches back to the master branch.

bin · high confidence

New Roda & Sequel demo application

A new demo application has been added to the repository, built with Roda and Sequel instead of the previous Rails-based example. This demo showcases an advanced file upload workflow using Uppy for direct-to-S3 uploads and background jobs for image processing. It includes full source code for the application logic, database migrations, and configuration, along with a README detailing setup requirements and implementation details.

demo · high confidence

Removals

Removal of FileSystem storage implementation

The FileSystem storage class has been removed from the lib/uploadie/storage directory. This change eliminates the ability to store uploaded files directly on the local file system using the previous directory and subdirectory configuration logic.

lib/uploadie/storage · high confidence

Removal of legacy metadata and filename plugins

The \preserve\_filename\, \store\_content\_type\, \store\_filename\, and \store\_filesize\ plugins have been removed from the library. Users relying on these plugins will no longer have automatic access to the \content\_type\, \original\_filename\, \extension\, and \size\ metadata fields on uploaded files, nor the filename preservation logic previously provided by the \preserve\_filename\ plugin. This change requires users to migrate to the new core metadata storage mechanisms or implement custom solutions to retain this file information.

lib/uploadie/plugins · high confidence

Architecture

Refactor file persistence and serialization into dedicated plugins

The file persistence and URL-safe serialization logic has been extracted from core components into the new \\_persistence\ and \\_urlsafe\_serialization\ plugins. The \\_persistence\ plugin provides a generic interface for atomic promotion and persistence strategies, which is now utilized by the \activerecord\ plugin to handle database row locking and JSON column detection. The \\_urlsafe\_serialization\ plugin centralizes the encoding and decoding of file data for endpoints, ensuring consistent serialization across the library.

lib/shrine/plugins · high confidence

Behavioural changes

Add custom styles for the demo application

A new CSS file (app.css) has been added to the demo assets to define specific layout and visibility rules. It sets the main container width to 800px and hides file upload preview images when their source is empty, improving the visual presentation of the demo interface.

demo/assets/css · high confidence

Demo app now uses Uppy for file uploads

The demo application's JavaScript has been rewritten to integrate the Uppy library for handling file uploads. This change introduces a modern upload interface, featuring a Dashboard for multiple file selections and a streamlined single-file upload flow with thumbnail generation. The implementation supports direct uploads to AWS S3 via presigned URLs as well as standard XHR uploads, ensuring that uploaded file metadata is correctly formatted for the backend.

demo/assets/js · high confidence

Demo app now uses dynamic derivation endpoint for thumbnails

The demo application has been updated to generate image thumbnails via a dynamic derivation endpoint rather than pre-computing them at upload time. The new ImageUploader configures the \derivation\_endpoint\ plugin to serve thumbnails on-demand through a dedicated route, while the \default\_url\ plugin ensures that thumbnail URLs are generated dynamically based on the requested derivative size. This shift allows for more flexible image processing and reduces storage overhead by only creating thumbnails when they are actually requested.

demo/uploaders · high confidence

Demo app reconfigured for S3 direct uploads, backgrounding, and derivatives

The demo application's configuration has been updated to support production-grade file handling. It now uses S3 for storage in production (falling back to local file system in development) and implements direct uploads via a presign endpoint that respects Uppy's query parameters. Backgrounding is handled by SuckerPunch, with jobs renamed to PromoteJob and DestroyJob to manage file promotion and deletion. The setup also enables eager derivatives processing, on-the-fly derivation endpoints, and uses Marcel for MIME type detection. Additionally, the demo now includes a Roda/Sequel variant with Forme integration for form handling.

demo/config · high confidence

Demo app restructured to use Roda routing

The demo application's routing layer has been rewritten to use the Roda framework, replacing the previous implementation. This change introduces a new base route class that configures essential plugins for rendering, CSRF protection, and asset handling, alongside Rack middleware for method overriding. Specific routes for managing albums (CRUD operations) and direct file uploads (supporting both S3 presigning in production and local filesystem uploads in development) are now defined within this Roda-based structure.

demo/routes · high confidence

Demo app updated to use Uppy v5 and Bootstrap 5

The demo application's layout has been updated to integrate Uppy v5.2.4 for file uploads and Bootstrap 5.1.1 for styling. This change replaces the previous UI components with the modern Uppy Dashboard and ensures the demo uses current versions of these libraries, improving the user experience for file uploads within the demo environment.

demo/views · high confidence

Migrate documentation site to Docusaurus 3

The Shrine documentation website has been rebuilt using Docusaurus 3, replacing the previous static site generator. This migration introduces a new navigation structure with dedicated sidebar sections for Guides, Plugins, External resources, and Release Notes (covering versions 1.x through 3.10). The site now features Algolia-powered search, a Dracula-soft syntax highlighting theme for code blocks, and disabled trailing slashes for cleaner URLs. Users will notice an updated layout and improved search capabilities when browsing the documentation.

website · high confidence

New FileSystem storage and updated Storage Linter

The FileSystem storage has been rewritten to use Ruby's Pathname class, introducing new \:permissions\ and \:directory\_permissions\ options to control file and folder access modes (defaulting to 0644 and 0755 respectively) and adding a \:clean\ option to automatically remove empty subdirectories. The storage linter has been updated to verify these new behaviors, including checks for the \delete\_prefixed\ method and the new permission settings.

lib/shrine/storage · high confidence

Redesigned home page with demo snippets and sponsor showcase

The website's home page now features a custom theme with a red color palette and dark code blocks, and includes a new 'Demo' section that displays Ruby code examples for file attachment and processing. Additionally, a dedicated 'Sponsors' component has been added to the home page to display supporter avatars and links, and a direct link to the RDoc documentation has been introduced in the main navigation.

website/src · high confidence

Rename gem from Uploadie to Shrine

The library has been renamed from Uploadie to Shrine. The main entry point class is now Shrine, and the previous lib/uploadie.rb file has been removed. Users must update their code to require 'shrine' and reference the Shrine class instead of Uploadie.

lib · high confidence

Rewritten album demo views with Uppy integration and Bootstrap 5 styling

The demo application's album views have been completely rewritten to use the Forme library for form generation and Uppy for client-side file uploads. The new interface is styled with Bootstrap 5 classes (e.g., \form-control\, \btn-primary\) and includes specific enhancements such as a cover photo upload with live preview, support for multiple photo uploads, and the ability to remove individual photos via a checkbox. The index view now displays albums in a table format with thumbnail previews, while the new and show views utilize a shared partial for consistent form handling.

demo/views/albums · high confidence

Shrine gem renamed and upgraded to version 3.10.0

The library formerly known as 'Uploadie' has been renamed to 'Shrine' and upgraded to version 3.10.0. This change introduces the core \Shrine::Attacher\ class for managing file attachments, the \Shrine::Attachment\ module for integrating with models, and the \Shrine::UploadedFile\ class for representing stored files, establishing the foundational API for file handling in this location.

lib/shrine · high confidence

Test coverage

Added acceptance tests for the demo album form; Added comprehensive test suites for core Shrine plugins; Added integration tests for ActiveRecord and Sequel backgrounding; Added test suite for storage implementations; Migrate test suite to Minitest::Spec and restructure test files; New test support infrastructure for ActiveRecord, Sequel, and logging assertions.

Dependencies

Shrine 3.0: Ruby 3.2+ requirement, AWS SDK v1, and Docusaurus 3 website

Shrine now requires Ruby 3.2 or higher and upgrades its core dependency on the Down library to version 5.1. The gemspec updates the AWS SDK dependency to aws-sdk-s3 \~\> 1.69 and adds development dependencies for Active Support 8.1 and Active Record 8.1. The demo application is restructured with a new Gemfile specifying Roda \~\> 3.36, Forme \~\> 1.8, and ImageProcessing \~\> 2.0, while the documentation website migrates to Docusaurus 3.10 with React 18. Additionally, the legacy uploadie gemspec is removed, and the main project Gemfile pins JSON to versions below 3.0 to prevent parsing errors.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 60 (-1.0)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (+0.0)
  • Architecture 100 → 73 (-26.5)
  • Maturity 58 → 58 (+0.0)
  • Readiness 50 → 50 (+0.0)
  • Security 67 → 74 (+7.4)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (3)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)

New (5)

  • CI runs a third-party container image from a mutable tag (.github/workflows/ci.yml)
  • Confusingly similar methods for triggering uploads. 'mirror_upload', 'mirror_upload_background', and 'trigger_mirror_upload' appear to do similar things (initiate a mirror upload) but with different execution contexts (sync vs async vs trigger). This is high cognitive load.
  • Inconsistent naming for defining transformation logic. 'derivation' vs 'process'. Both define a block-based transformation on files, but use different verbs.
  • Inconsistent naming for endpoint configuration methods. One uses 'derivation_endpoint' while the other uses 'download_endpoint'. While the domain differs, the pattern for defining HTTP endpoints in plugins is inconsistent.
  • Projects may be oversized for their cohesion

Changes since last survey

  • 3 commits — 3 feature/other, 0 fixes

By area

  • (root) — 2 commits
  • .github/workflows — 1 commit

Notable commits

  • change: Bump to 3.10.0
  • change: Pin JSON gem to < 3
  • change: Try pinning Docker image for MinIO in CI

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

shrinerb/shrine was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 95c5316e9008a4b9dc4b069d6d1fc0126943407c — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.