On this page
Overview
Ransack is a Ruby gem for object-based searching, filtering, and sorting on ActiveRecord. Controllers build a search object and views use helpers such as search_form_for and sort_link to create query interfaces over columns and associations, executing through the application's existing database instead of requiring a separate search service.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Search ActiveRecord columns and associations
Simple mode turns attribute-and-predicate query parameters into ActiveRecord relations and supports association paths, compound attribute searches, and other SQL-backed filters.
Build search and sorting interfaces with Rails helpers
search_form_for creates search fields while sort_link generates sortable links for tables and lists. A Turbo-aware form helper is also available.
Sources: [4]
Extend queries with advanced predicates and custom ransackers
Advanced mode, custom predicates, ransackers, and i18n can express more specialized search behavior while remaining integrated with Rails and ActiveRecord.
Sources: [1]
Best fit
Fits admin screens and database-backed list filtering
It is useful for back-office lists, customer lookup, catalog filtering, and similar interfaces that do not justify operating a separate full-text search infrastructure.
Sources: [1]
Before adoption
Do not remain on versions vulnerable to the pre-v5.0.2 crafted-key DoS
Version 5.0.2 is a security release fixing quadratic parsing of very long q condition keys and sort values. Attribute allowlisting does not mitigate that issue, so affected deployments should upgrade.
Sources: [2]
Explicitly authorize searchable and sortable attributes and associations
Since v4.0, model columns are not searchable or sortable by default. ransackable_attributes, ransackable_associations, related methods, or an appropriate Strong Parameters design should limit what external input can query.
Official sources
- [1]Ransack v5.0.2 README(2026-10-03)
- [2]Ransack v5.0.2 security release(2026-10-03)
- [3]Ransack v5.0.2 gemspec(2026-10-03)
- [4]Ransack simple mode documentation(2026-10-03)
- [6]Ransack MIT license(2026-10-03)
Supplemental curator note
Ransack is useful when a Rails application needs database-backed search screens without operating a separate search service such as Elasticsearch. Searchable attributes and associations still need explicit authorization, and deployments should not remain on versions before the v5.0.2 crafted-key DoS fix.
Try it in 3 steps
- 1
Add the security-fixed Ransack version
v5.0.2 fixes the crafted-search-key DoS. Confirm Rails 7.2+ and Ruby 3.1+ compatibility.
Add gem 'ransack', '5.0.2' to Gemfile, then run bundle install - 2
Allowlist searchable model attributes
Since v4, model columns are not searchable by default. Explicitly allow only fields the search UI needs.
Define self.ransackable_attributes in the target ActiveRecord model - 3
Add the search to the controller and view
Build the search object in the controller and use search_form_for @q in the view to add search fields.
@q = Person.ransack(params[:q]); @people = @q.result(distinct: true)
Growth
Growth trends · Last 30 days
5,858 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 55
- Open PRs
- 1
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- search
- search-interface
- ruby
- ruby-gem
- ruby-library
- ruby-on-rails
- activerecord
- sql
- rails
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Draper5,277 Stars
2 shared tag(s) · Same language
wrap Rails models with decorators and view models so presentation logic stays out of models and global helpers
Ruby - Jekyll51,707 Stars
1 shared tag(s) · 1 shared category(s) · Same language
generate blog-aware static sites from Markdown and Liquid
Ruby - Homebrew49,876 Stars
1 shared tag(s) · 1 shared category(s) · Same language
manage macOS and Linux software through the
Rubybrewpackage workflow - Vagrant27,211 Stars
1 shared tag(s) · 1 shared category(s) · Same language
define portable development environments across providers with a Vagrantfile
Ruby - Kamal14,627 Stars
1 shared tag(s) · 1 shared category(s) · Same language
deploy Dockerized web apps to bare metal or cloud VMs over SSH and switch traffic with kamal-proxy for zero-downtime releases
Ruby - ActiveAdmin9,713 Stars
1 shared tag(s) · 1 shared category(s) · Same language
embed an administration engine in Rails and define resources and actions through a DSL
Ruby
Report incorrect information
Tell us if any listing information is incorrect or outdated.