OSS Tanbou

add searching, filtering, and sorting to ActiveRecord-backed Rails apps without a separate search service

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
5,858
Primary language
Ruby
License
MIT
Repository last updated
Oct 1, 2026
On this page

Overview

Ransack is a Ruby gem for object-based searching, filtering, and sorting on ActiveRecord. Controllers build a search object and views use helpers such as search_form_for and sort_link to create query interfaces over columns and associations, executing through the application's existing database instead of requiring a separate search service.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Search ActiveRecord columns and associations

Simple mode turns attribute-and-predicate query parameters into ActiveRecord relations and supports association paths, compound attribute searches, and other SQL-backed filters.

Sources: [1][4]

Build search and sorting interfaces with Rails helpers

search_form_for creates search fields while sort_link generates sortable links for tables and lists. A Turbo-aware form helper is also available.

Sources: [4]

Extend queries with advanced predicates and custom ransackers

Advanced mode, custom predicates, ransackers, and i18n can express more specialized search behavior while remaining integrated with Rails and ActiveRecord.

Sources: [1]

Best fit

Fits admin screens and database-backed list filtering

It is useful for back-office lists, customer lookup, catalog filtering, and similar interfaces that do not justify operating a separate full-text search infrastructure.

Sources: [1]

Before adoption

Do not remain on versions vulnerable to the pre-v5.0.2 crafted-key DoS

Version 5.0.2 is a security release fixing quadratic parsing of very long q condition keys and sort values. Attribute allowlisting does not mitigate that issue, so affected deployments should upgrade.

Sources: [2]

Explicitly authorize searchable and sortable attributes and associations

Since v4.0, model columns are not searchable or sortable by default. ransackable_attributes, ransackable_associations, related methods, or an appropriate Strong Parameters design should limit what external input can query.

Sources: [4][5]

v5.0.2 requires ActiveRecord 7.2+ and Ruby 3.1+

The v5.0.2 gemspec requires ActiveRecord and ActiveSupport 7.2 or later and Ruby 3.1 or later, while its README lists Rails 7.2, 8.0, and 8.1 as supported.

Sources: [3][1]

Official sources

  1. [1]Ransack v5.0.2 README(2026-10-03)
  2. [2]Ransack v5.0.2 security release(2026-10-03)
  3. [3]Ransack v5.0.2 gemspec(2026-10-03)
  4. [4]Ransack simple mode documentation(2026-10-03)
  5. [5]Ransack authorization documentation(2026-10-03)
  6. [6]Ransack MIT license(2026-10-03)
Supplemental curator note

Ransack is useful when a Rails application needs database-backed search screens without operating a separate search service such as Elasticsearch. Searchable attributes and associations still need explicit authorization, and deployments should not remain on versions before the v5.0.2 crafted-key DoS fix.

Try it in 3 steps

  1. 1

    Add the security-fixed Ransack version

    v5.0.2 fixes the crafted-search-key DoS. Confirm Rails 7.2+ and Ruby 3.1+ compatibility.

    Add gem 'ransack', '5.0.2' to Gemfile, then run bundle install
  2. 2

    Allowlist searchable model attributes

    Since v4, model columns are not searchable by default. Explicitly allow only fields the search UI needs.

    Define self.ransackable_attributes in the target ActiveRecord model
  3. 3

    Add the search to the controller and view

    Build the search object in the controller and use search_form_for @q in the view to add search fields.

    @q = Person.ransack(params[:q]); @people = @q.result(distinct: true)
Check the official README

Growth

Growth trends · Last 30 days

5,858 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
55
Open PRs
1

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • search
  • search-interface
  • ruby
  • ruby-gem
  • ruby-library
  • ruby-on-rails
  • activerecord
  • sql
  • rails
Stars
5,858
Forks
817
Watchers
78
Open issues
1
Contributors
217
Owner type
Organization
Primary language
Ruby
License
MIT
Repository last updated
Oct 1, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?