bundler-audit
https://github.com/rubysec/bundler-audit
Ruby
Patch-level verification for Bundler
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
1 Subscribers
Add a CodeTriage badge to bundler-audit
Help out
- Issues
- Bump activerecord from 3.2.10 to 7.1.5.2 in /spec/bundle/unpatched_gems_with_dot_configuration
- Check ruby version from lockfile for advisories
- Add support for expiring advisory ignores
- Add inherit config option
- Create a new bundler-audit release then figure out how to get the gem published
- Dedup the scanner report for unpatched gems with more than one platform
- Duplicate vulnerabilities reported for gems that have multiple arch specs on the lockfile
- Feature request: ability to generate more detailed report
- Separate lockfile parsing from vulnerability scanning
- Feature request: EoL version tracking
- Docs
- Subscribe to help with docs for this repo and come back later