bundler-audit
https://github.com/rubysec/bundler-audit
Ruby
Patch-level verification for Bundler
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
1 Subscribers
Add a CodeTriage badge to bundler-audit
Help out
- Issues
- Bundler audit is not thread safe
- Add --no-exit-on-warn flag that exits with 0 even when vulnerable
- Support scanning .gemspec files
- Refactor Bundler::Audit::Scanner#initialize
- Ability to define the Gemfile via BUNDLE_GEMFILE
- Exits normally when --gemfile-lock is not a lock file, should exit with error
- Allow for ignoring insecure sources.
- Remove tests files and other config-related files from the gem packages
- Introduce logic for cvss_v4 severity
- Request - HTML output
- Docs
- Subscribe to help with docs for this repo and come back later