brakeman
https://github.com/presidentbeef/brakeman
Ruby
A static analysis security vulnerability scanner for Ruby on Rails applications
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
3 Subscribers
Add a CodeTriage badge to brakeman
Help out
- Issues
- WeakRSAKey check page is missing
- Allow `--only-files` et al. to function with 'leading dot' notation for files
- Add CSV as an explicit dependency
- Output `originalBaseUriIds` for SARIF report
- SARIF reports generate broken artifact URIs when nonstandard path is used
- Option to process additional/non-standard config files
- XSS False positive inside = javascript_tag
- False positive when methods chained on permitted params
- Accept ActiveStorage::Filename#sanitized and to_i as safe
- Do not treat private methods as routable
- Docs
- Subscribe to help with docs for this repo and come back later