3 ms·
For those who haven't yet come across it, bundler-audit is a very useful tool to pick up any old and/or insecure gems in your application. It should be part of
by jlangenauer 8y ago
For those who haven't yet come across it, bundler-audit is a very useful tool to pick up any old and/or insecure gems in your application. It should be part of your CI pipeline, or at a minimum, run locally every so often.
https://github.com/rubysec/bundler-audit https://github.com/rubysec/bundler-audit
- thibaut_barrere 8y agoNote that it won't yet detect this specific vulnerability: https://github.com/rubysec/ruby-advisory-db/pull/386 https://github.com/rubysec/ruby-advisory-db/pull/386
- TicklishTiger 8y agoThat's great. Is there also a bundler-meta-audit the somewhere, so I can audit bundler-audit and it's dependencies? If not, maybe we should start a kickstarter for it?