brakeman
https://github.com/presidentbeef/brakeman
Ruby
A static analysis security vulnerability scanner for Ruby on Rails applications
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
3 Subscribers
Add a CodeTriage badge to brakeman
Help out
- Issues
- Truncate Session Secret in HTML Report
- Detect open linking - url_for(params) without only_path or host
- Removing a file access warning
- Can't fix a "Possible unprotected redirect"
- Identify cases where exception messages are printed to users
- Render with inline option classified incorrectly
- False positive: Command Injection
- Idea: brakeman should check file execution permissions
- Somehow mark models as non-user controllable
- Feedback request: Incremental scans
- Docs
- Subscribe to help with docs for this repo and come back later