brakeman
https://github.com/presidentbeef/brakeman
Ruby
A static analysis security vulnerability scanner for Ruby on Rails applications
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
3 Subscribers
Add a CodeTriage badge to brakeman
Help out
- Issues
- Remove command injection false positives for splatted args
- fix(scanner): skip alternative-Ruby `.ruby-version` strings (#1960)
- Support reading config from ignore file
- Resolve index_by(&:itself) on literal arrays to hash literals
- Hash lookup on frozen constant should untaint the result
- Treats "jruby-10.0.2.0" in .ruby-version as outdated Ruby 0.0.2
- Provide a way to report warnings only from some files/directories while scanning the full app
- `Brakeman::SexpProcessor#process`: Type should be a Symbol
- Feature: Check Mailer templates for html injection
- Allow Brakeman to determine the Rails configuration by querying `Rails.application.config`
- Docs
- Subscribe to help with docs for this repo and come back later