brakeman
https://github.com/presidentbeef/brakeman
Ruby
A static analysis security vulnerability scanner for Ruby on Rails applications
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
3 Subscribers
Add a CodeTriage badge to brakeman
Help out
- Issues
- Unvalidated `redirect_back` false negatives
- brakeman still references haml 4 - which is a bit long in the tooth (Haml::Filter::Coffee class vs. module)
- https://github.com/presidentbeef/brakeman/issues/1841
- Support non-standard gemfile naming for dual booting Rails apps
- False negatives due to --skip-libs ignoring app/ files.
- with_content for ViewComponent flagged as dynamic render path
- Check Graphql end-point for vulnerabilities
- Controller with "log" in pathname excluded from scan
- UnsafeReflection requires array to be defined with values strictly in the context of the execution
- Check for signed_id/Global ID usage without specified purpose
- Docs
- Subscribe to help with docs for this repo and come back later