{"repo":"rubysec/bundler-audit","free":true,"listed":false,"github":"https://github.com/rubysec/bundler-audit","clone":"git clone https://github.com/rubysec/bundler-audit.git","description":"Patch-level verification for Bundler","language":"Ruby","stars":2758,"topics":["bundler-audit","ruby-advisory-db","ruby","dependency-checker","patch-management","security","security-tools","security-audit"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"bundler-audit Homepage Issues Documentation Description Patch-level verification for [bundler]. Features Checks for vulnerable versions of gems in Gemfile.lock . Checks for insecure gem sources ( http:// and git:// ). Allows ignoring certain advisories that have been manually worked around. Prints advisory information. Does not require a network connection. Synopsis Audit a project's Gemfile.lock : Update the [ruby-advisory-db] that bundle audit uses: Update the [ruby-advisory-db] and check Gemfile.lock (useful for CI runs): Checking the Gemfile.lock without updating the [ruby-advisory-db]: Ignore specific advisories: Checking a custom Gemfile.lock file: Output the audit's results in JSON: Output the audit's results in JSON, to a file: Rake Tasks Bundler-audit provides rake tasks for checking the code and for updating its vulnerability database. Simply add the following code to the Rakefile : The following rake tasks will then become available: Configuration File bundler-audit also supports a per-project configuration file: .bundler-audit.yml : ignore: \\[Array\\ \\] - A list of advisory IDs to ignore. You can provide a path to a config file using the --config flag: Requirements [git] [ruby] = 2.0.0 [rubygems] = 1.8 [thor] 1.0 [bundler] = 1.2.0 Install Git Debian / Ubuntu: RedHat / Fedora: Alpine Linux: macOS: Contributing 1. https://github.com/rubysec/bundler-audit/fork 2. git clone YOUR FORK URI 3. cd bundler-audit/ 4. bundle install 5. bundle exec rake spec 6. git checkout -b","default_branch":null,"files":null,"tree":[],"storefront":"/r/rubysec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/rubysec/bundler-audit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}